substack-tools

Warn

Audited by Socket on May 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's goals mostly match its capabilities, but it relies on an unofficial reverse-engineered library, asks for a raw Substack session cookie copied from the browser, and can perform irreversible public publishing actions. Data flow seems mainly to Substack rather than an obvious attacker endpoint, so this is not confirmed malware, but credential handling and supply-chain trust are materially risky.

Confidence: 85%Severity: 76%
Audit Metadata
Analyzed At
May 1, 2026, 03:03 PM
Package URL
pkg:socket/skills-sh/hoangvantuan%2Fclaude-plugin%2Fsubstack-tools%2F@504940c690b4c32959bf5a3922c65917df03ae6e