capture-x-ai-lists
Warn
Audited by Socket on Apr 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the archival purpose broadly matches the capabilities, but trust and data-flow integrity are weakened by reliance on third-party X access tooling that may receive browser cookies, plus a documented mismatch between Agent Reach's public upstream naming and the skill's claimed xreach path. Local file access is proportionate, but credential forwarding and untrusted-content processing make this a medium-high risk skill rather than benign.
Confidence: 84%Severity: 76%
Audit Metadata