tweetclaw
Warn
Audited by Socket on Sep 9, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is internally coherent and likely official to Xquik, so there is little evidence of malware or deceptive installation. However, it routes Twitter activity and the API key through a third-party intermediary instead of official X APIs, and it enables autonomous public posting/DM actions plus monitoring and bulk extraction, making the overall security risk medium-high despite plausible purpose alignment.
Confidence: 89%Severity: 66%
Audit Metadata