twitter-digest

Warn

Audited by Socket on Jul 19, 2026

1 alert found:

Anomaly
AnomalyLOW
install.sh

This is a remote-code bootstrapper with significant supply-chain risk characteristics: it clones and executes code from a configurable remote repository/tag, and on macOS it may additionally download and execute a remote shell script via curl in a Terminal automation flow. No direct malicious payload behavior (exfiltration/credential theft/reverse shells) is evident in this fragment alone, but the absence of integrity verification and the environment-controlled REPO/TAG parameters make it a high-impact installation vector. The effective malware/intent risk cannot be confirmed without inspecting the fetched `install.sh` and cloned `install.py` implementation.

Confidence: 60%Severity: 68%
Audit Metadata
Analyzed At
Jul 19, 2026, 08:51 PM
Package URL
pkg:socket/skills-sh/BofAI%2Fskills%2Ftwitter-digest%2F@1603237620479ea700bff014f814f63a46e2838a055dc1df3c2bede719bc5d79
Security Audit — socket — twitter-digest