social-poster-hardened

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose matches social posting, but its trust model does not. The main issue is credential and content routing through an unverified Replit-hosted API with a hardcoded key, plus an unpinned `npx` install path. This is not confirmed malware, but it presents high security risk and disproportionate trust requirements for a posting skill.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
Apr 21, 2026, 06:35 PM
Package URL
pkg:socket/skills-sh/faberlens%2Fhardened-skills%2Fsocial-poster-hardened%2F@abc5ac6b727aed79f06e821886fb6f392048749f
Security Audit — socket — social-poster-hardened