post-to-x

Warn

Audited by Socket on Jun 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core posting capability matches the skill’s stated purpose, but it uses browser automation specifically framed as anti-bot bypass and recommends a curl|bash installer path for Bun. There is no clear credential-harvesting or third-party exfiltration behavior, yet the combination of public-posting capability, anti-detection automation, and supply-chain exposure makes the skill medium risk rather than benign.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 11:11 AM
Package URL
pkg:socket/skills-sh/GPTtang%2Fskill-atlas%2Fpost-to-x%2F@808cc9261dcf0e86e4ec11876b3f8e3c620210b917062c2a99f565dd2ce64033
Security Audit — socket — post-to-x