tiktok-warmup

Warn

Audited by Socket on May 7, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
runNightlyAudit.md

No explicit malware behavior is shown in this fragment; it is an automation/orchestration prompt. The main risk is supply-chain and operational integrity: the workflow relies on high-privilege credentials (Supabase service role), delegates behavior to local protocol/rule files, and can perform authenticated mutations (Airtable PATCH) and automated repository changes with possible auto-merge. External Telegram escalation adds a side-channel for metadata. The security posture hinges on integrity of the referenced protocol/rules and the least-privilege/guardrails in the agent tooling, which are not included in this snippet.

Confidence: 60%Severity: 65%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent for TikTok account warmup and management, but it carries elevated risk because it automates social-platform actions, handles several sensitive credentials, includes anti-detection/ban-evasion guidance, and instructs a transitive skill update on load. I see no clear credential-harvesting endpoint or hidden exfiltration behavior in the provided text, so this is not confirmed malware.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
May 7, 2026, 09:27 AM
Package URL
pkg:socket/skills-sh/frahman5%2Ffstack%2Ftiktok-warmup%2F@7f8161da98633eba34943b369760c1dab32b9287