hootsuite-debug-bundle
Warn
Audited by Socket on Sep 9, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s network targets and credentials are aligned with Hootsuite troubleshooting, and there is no malicious installer or third-party credential forwarding. But the actual collection script is inconsistent with the skill’s own redaction rules: it saves raw profile and scheduled-post API payloads locally, likely including account metadata and possibly content fields that the instructions explicitly prohibit. This is a data-minimization and support-bundle scoping problem, not confirmed malware.
Confidence: 91%Severity: 53%
Audit Metadata