postiz

Warn

Audited by Socket on Jul 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities are largely aligned with social publishing, and its Postiz API model matches official docs. The main risk is trust concentration in the undocumented `mktg` adapter, which receives the Postiz API key and performs the network actions; without verified provenance for that adapter, credential forwarding and execution trust remain medium-high concerns.

Confidence: 79%Severity: 68%
Audit Metadata
Analyzed At
Jul 14, 2026, 02:08 PM
Package URL
pkg:socket/skills-sh/MoizIbnYousaf%2Fmarketing-cli%2Fpostiz%2F@3452f5e9a6986ad2eb48fdca3a103d4414ceabc6ca67886eb8840a220ee01874
Security Audit — socket — postiz