substackctl
Warn
Audited by Socket on Aug 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s capabilities mostly match its stated Substack-management purpose, and its human-confirmation rules are thoughtful, but it relies on an unverified hand-installed CLI and likely forwards a live Substack session cookie into an unofficial binary using private endpoints. That combination creates substantial supply-chain and credential-handling risk without enough provenance to treat as benign.
Confidence: 86%Severity: 84%
Audit Metadata