saved-searches

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core purpose is plausible, but it relies on pasting unreviewed JavaScript into DevTools on an authenticated x.com session, enabling account actions and potential broader page access. No external installer or obvious exfiltration endpoint is shown, so this is not confirmed malware, but the unofficial workflow, mismatch with X help documentation, and broadened scraping scope make it medium risk.

Confidence: 80%Severity: 54%
Audit Metadata
Analyzed At
Apr 15, 2026, 01:44 PM
Package URL
pkg:socket/skills-sh/nirholas%2FXActions%2Fsaved-searches%2F@8ae872feb4845669c7a8550a05551756a27fa782