social-autoposter

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The social-autoposter skill presents a coherent, purpose-aligned feature set with proportionate credentials and data flows. It relies on local config/env data to drive browser/API-based posting and engagement while logging activity to a local database. There are no clear indicators of malicious intent (no unverifiable binaries, credential harvesting, or exfiltration to unknown endpoints). The main risks lie in potential autonomous actions and data exposure through logs; these are mitigated by rate limits and explicit manual post workflows, but require careful runtime governance and access controls. Overall, the footprint is Benign with elevated suspicion only around autonomy and data handling in environments with weak security controls.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 08:21 PM
Package URL
pkg:socket/skills-sh/m13v%2Fskill-social-autoposter%2Fsocial-autoposter%2F@6a5c983b6aba0c54b75a435ecf1f738eb02e6fa6