substack-publish

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s publishing purpose is coherent, and it has no installer or obvious malware behavior, but it relies on a manually extracted browser session cookie and forwards that credential through an external MCP backend/gateway whose exact `substack-*` implementation is not provided. The main risk is sensitive credential forwarding and unverifiable backend data handling, not confirmed malicious intent.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Sep 2, 2026, 09:17 PM
Package URL
pkg:socket/skills-sh/calionauta%2Fagent-sync-public%2Fsubstack-publish%2F@25afbcb7c2797dbbac756cb7587b714f8e0dbdc50ab548e2aefc865a21fc8af1
Security Audit — socket — substack-publish