wjs-promoting-skills

Warn

Audited by Socket on May 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned but high risk because it enables unattended real-world public posting on the user's X account every day. The main concerns are autonomous posting, ingestion of external content into generation, and reliance on a non-official posting CLI with unclear provenance; this looks risky and overpowered for an agent skill, but not clearly malicious.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
May 21, 2026, 01:00 AM
Package URL
pkg:socket/skills-sh/jianshuo%2Fclaude-skills%2Fwjs-promoting-skills%2F@387ca28174313bc974e4a201eadca3de72c201f4
Security Audit — socket — wjs-promoting-skills