laniameda-x-post

Warn

Audited by Socket on Apr 17, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
references/x-tweet-fetcher.md

SUSPICIOUS: the stated scraping purpose generally matches the documented behavior, but the full feature set relies on a third-party browser/plugin service installed via transitive trust paths and expands into broad web/search scraping. No clear credential theft or overt exfiltration is documented, yet the external install chain, opaque localhost proxying, and untrusted-content processing make this a medium-risk skill rather than benign.

Confidence: 83%Severity: 58%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core purpose is coherent, but the skill routes tweet retrieval through a third-party FxTwitter proxy, recursively ingests untrusted external content with subagents/browser automation, and depends on an unverifiable local fetcher script outside official package channels. User approval limits the highest-impact writes, but the install trust and indirect prompt-injection exposure make this a medium-high risk skill.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Apr 17, 2026, 10:31 AM
Package URL
pkg:socket/skills-sh/Michailbul%2Flaniameda-skills%2Flaniameda-x-post%2F@e460278ec4d8d885064a1832302721305b0a6d6d