social-cli

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned and its install/data-flow story is largely coherent: same-org source repo, local build from source, and direct use of social platform credentials for social platform actions. The main risk is not hidden exfiltration but autonomy: it is explicitly built to let an agent run unattended social posting/engagement loops with live credentials, creating high real-world action risk despite otherwise reasonable provenance.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Apr 23, 2026, 06:39 AM
Package URL
pkg:socket/skills-sh/letta-ai%2Fskills%2Fsocial-cli%2F@fc1d05ac883a74300c744930f2b7843368d24908