x-api

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent with X posting/reading, and the data flow is meant for official X endpoints, but the skill’s entire trust model rests on an undocumented local script that receives all X credentials. Because that executable is unverifiable and handles secrets, the skill carries high security risk even without direct evidence of malicious exfiltration.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Apr 1, 2026, 05:58 AM
Package URL
pkg:socket/skills-sh/notque%2Fclaude-code-toolkit%2Fx-api%2F@e4ddebe1200e0cad996b71e214a6d713301288cb