substack-tools
Warn
Audited by Socket on May 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's goals mostly match its capabilities, but it relies on an unofficial reverse-engineered library, asks for a raw Substack session cookie copied from the browser, and can perform irreversible public publishing actions. Data flow seems mainly to Substack rather than an obvious attacker endpoint, so this is not confirmed malware, but credential handling and supply-chain trust are materially risky.
Confidence: 85%Severity: 76%
Audit Metadata