twitter-post

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the workflow is purpose-aligned for Twitter posting and includes strong approval gates, but it relies on a vendor-specific external CLI and a peer preflight skill whose full provenance and command documentation are only partially verified. I found no clear credential-harvesting, stealth, or off-purpose behavior, so the main risk is supply-chain and transitive trust rather than confirmed malicious intent.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Sep 9, 2026, 03:59 AM
Package URL
pkg:socket/skills-sh/ohmyskyhigh%2Fthreadwave-skill%2Ftwitter-post%2F@181e9c913a62608762b803400f931a662140341da2ae487637b9fdc589e12206
Security Audit — socket — twitter-post