last30days

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/lib/vendor/bird-search/lib/cookies.js

This module is not overtly malware by itself (no execution of untrusted code beyond a normal dependency import, and no direct exfiltration/network calls are present). However, it performs high-sensitivity credential extraction by targeting x.com auth cookies (auth_token and ct0) from env/CLI and optionally from local browser profiles, then returns a reusable Cookie header to the caller. The main security concerns are (1) credential-handling risk due to returning session secrets and (2) supply-chain trust in the dynamically imported cookie-access dependency.

Confidence: 66%Severity: 64%
Audit Metadata
Analyzed At
May 18, 2026, 03:48 AM
Package URL
pkg:socket/skills-sh/mvanhorn%2Flast30days-skill%2Flast30days%2F@55d282051b95b81f850ad37b6853b2dfb1958f60
Security Audit — socket — last30days