x-tweet-fetcher

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated scraping purpose generally matches the documented behavior, but the full feature set relies on a third-party browser/plugin service installed via transitive trust paths and expands into broad web/search scraping. No clear credential theft or overt exfiltration is documented, yet the external install chain, opaque localhost proxying, and untrusted-content processing make this a medium-risk skill rather than benign.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
Apr 17, 2026, 10:30 AM
Package URL
pkg:socket/skills-sh/Michailbul%2Flaniameda-skills%2Fx-tweet-fetcher%2F@4c25f4c8d39a2d4249a52d24a302eaa0f7f06f14