xbird

Warn

Audited by Socket on Jul 4, 2026

4 alerts found:

Securityx3Anomaly
SecurityMEDIUM
skills/xbird-rest-api/SKILL.md
AnomalyLOW
skills/xbird-acp/SKILL.md

SUSPICIOUS: The skill is mostly aligned with its stated ACP/Twitter purpose, but it requires raw Twitter session cookies and depends on a third-party Railway-hosted attestation endpoint to establish encryption trust. Data flows are coherent, yet the credential sensitivity and non-first-party attestation host make this medium risk rather than benign.

Confidence: 100%Severity: 60%
SecurityMEDIUM
SKILL.md
SecurityMEDIUM
skills/xbird/SKILL.md
Audit Metadata
Analyzed At
Jul 4, 2026, 02:58 PM
Package URL
pkg:socket/skills-sh/checkra1neth%2Fxbird-skill%2Fxbird%2F@3208eb2bb227b93bbc31e94659d0f7efdee488c3
Security Audit — socket — xbird