capture-x-ai-lists

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the archival purpose broadly matches the capabilities, but trust and data-flow integrity are weakened by reliance on third-party X access tooling that may receive browser cookies, plus a documented mismatch between Agent Reach's public upstream naming and the skill's claimed xreach path. Local file access is proportionate, but credential forwarding and untrusted-content processing make this a medium-high risk skill rather than benign.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
Apr 19, 2026, 04:35 PM
Package URL
pkg:socket/skills-sh/JimLiuxinghai%2Fjim-skills%2Fcapture-x-ai-lists%2F@9c6e4d37a5b0815af5b79c35a6c900f67d4d8d65
Security Audit — socket — capture-x-ai-lists