twitter-reply

Warn

Audited by Socket on Sep 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's posting capability matches its stated Twitter-reply purpose, but it depends on an external ThreadWave CLI/service and another skill, creating meaningful supply-chain and credential/data-routing risk. The approval gates make it less likely to be outright malicious, but the trust and public-posting footprint are substantial enough to treat it as medium-high risk until the CLI/source provenance is verified.

Confidence: 78%Severity: 72%
Audit Metadata
Analyzed At
Sep 1, 2026, 11:18 AM
Package URL
pkg:socket/skills-sh/ohmyskyhigh%2Fthreadwave-skill%2Ftwitter-reply%2F@0253bcd67ec5272bc52e7220afc29aedbf11329fc6cef769805f579899df7ffc
Security Audit — socket — twitter-reply