social-reply-bot

Warn

Audited by Socket on Aug 20, 2026

5 alerts found:

Securityx3Anomalyx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its stated purpose matches its capabilities, but the footprint is risky: raw GitHub pipe-to-shell install, third-party browser automation, and autonomous public posting/karma-building on social platforms. This looks more like growth/spam automation than a narrowly scoped integration, with meaningful supply-chain and account-misuse risk.

Confidence: 87%Severity: 82%
SecurityMEDIUM
install.sh

This installer is primarily an automation/persistence setup script with significant supply-chain and credential-exposure risk characteristics. It repeatedly pulls and executes remote code (git clone/pull; pip install from requirements without hashes/lock pinning; optional npm global install without pinning) and immediately executes repository code via init_db(). It also establishes persistence via a macOS LaunchAgent and embeds an API key into a persisted plist. No explicit malicious payloads are visible in the snippet, so certainty of malware is not justified; however, the combination of unpinned remote execution + persistence + secret embedding warrants a security review of the referenced repository code and the LaunchAgent template/entrypoint before use.

Confidence: 60%Severity: 78%
AnomalyLOW
warmup_reddit.py

This module appears to implement automated Reddit engagement “warmup/karma” by scraping posts, using Anthropic to generate comments, and posting them via browser automation. It shows no strong indicators of classic malware (no clear host compromise/exfiltration/persistence in the provided fragment), but it does present meaningful security/policy risk due to automated third-party site interaction and posting. The code also alters sys.path to prioritize local imports, which increases the impact of any repository/deployment tampering. Confidence is limited because the excerpt is incomplete/garbled (unfinished/undefined parts), so the exact behavior and any additional risk-bearing code outside the snippet cannot be fully verified.

Confidence: 60%Severity: 60%
SecurityMEDIUM
bot/browser.py

No clear evidence of intrinsic malware, credential theft, or data exfiltration within this Python snippet. However, the module creates a significant supply-chain/usage risk by executing an external browser CLI via subprocess.run with shell=True while interpolating caller-controlled parameters into a shell command string. If inputs (url/path/ref/text/key/args) are attacker-controlled, this can enable command injection or unintended command execution/sabotage. Additionally, parsing untrusted stdout with json.loads can create denial-of-service or data-integrity issues if the external tool outputs unexpected large/adversarial data.

Confidence: 74%Severity: 70%
AnomalyLOW
setup.sh

This setup script appears to be a legitimate automation/bot provisioning wrapper, but it carries meaningful supply-chain and persistence risk: it performs high-impact pip and global npm installs without integrity controls shown here, scaffolds a credential/config file, executes local project code during DB initialization, and installs a macOS LaunchAgent for recurring execution. No explicit malicious behavior or data exfiltration is evident in this fragment; any malware would most likely be in the installed dependencies or the referenced local bot modules/plist target behavior.

Confidence: 62%Severity: 58%
Audit Metadata
Analyzed At
Aug 20, 2026, 02:30 PM
Package URL
pkg:socket/skills-sh/mguozhen%2Fsocial-bot%2Fsocial-reply-bot%2F@890c8f2a8b559b6775dab648660c71ba2c3a05b4
Security Audit — socket — social-reply-bot