last30days

Warn

Audited by Socket on May 9, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/lib/vendor/bird-search/lib/cookies.js

This module is not overtly malware by itself (no execution of untrusted code beyond a normal dependency import, and no direct exfiltration/network calls are present). However, it performs high-sensitivity credential extraction by targeting x.com auth cookies (auth_token and ct0) from env/CLI and optionally from local browser profiles, then returns a reusable Cookie header to the caller. The main security concerns are (1) credential-handling risk due to returning session secrets and (2) supply-chain trust in the dynamically imported cookie-access dependency.

Confidence: 66%Severity: 64%
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and visible workflow are mostly coherent for recent-trend research, and there is no direct evidence of credential theft or malicious exfiltration. However, it relies on executing an opaque vendored engine sourced from a personal GitHub project and processes untrusted external content with write capability, so the overall risk is medium rather than benign.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
May 9, 2026, 03:47 AM
Package URL
pkg:socket/skills-sh/nexu-io%2Fopen-design%2Flast30days%2F@e13cbc419c066d5b26608792cfcb8755406cc881
Security Audit — socket — last30days