x-twitter-publish

Warn

Audited by Socket on Jul 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose matches social publishing, but its actual footprint relies on a third-party intermediary for both X credentials and account actions. No obvious malware or installer abuse is present, yet the credential relay, optional TOTP handling, inbox/DM scope, and autonomous public-action capability make this a high-trust integration with significant security risk.

Confidence: 86%Severity: 76%
Audit Metadata
Analyzed At
Jul 29, 2026, 05:19 PM
Package URL
pkg:socket/skills-sh/lnvestor%2Ftwitr-skills%2Fx-twitter-publish%2F@7a42e50672ca639fd36e69e8f1288223e93ed11c8e55569c7e0e9083f8006237
Security Audit — socket — x-twitter-publish