x-twitter-publish

Warn

Audited by Socket on Jul 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose matches social publishing, but its actual footprint relies on a third-party intermediary for both X credentials and account actions. No obvious malware or installer abuse is present, yet the credential relay, optional TOTP handling, inbox/DM scope, and autonomous public-action capability make this a high-trust integration with significant security risk.

Confidence: 86%Severity: 76%
Audit Metadata
Analyzed At
Jul 27, 2026, 09:20 PM
Package URL
pkg:socket/skills-sh/lnvestor%2Ftwitr-skills%2Fx-twitter-publish%2F@ce60f89a76d9819a8957a9da2ca214af4de95ea4260340582142c65b1e92a312
Security Audit — socket — x-twitter-publish