social-auto-publisher

Warn

Audited by Socket on Aug 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The overall purpose is coherent for a social publishing skill, and the named installs are ordinary npm dependencies. The main risk is not hidden malware but the skill’s high-impact autonomous posting/reply capability, combined with sensitive session/cookie access and untrusted external content feeding write actions; absent code, endpoint integrity cannot be fully confirmed.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Aug 8, 2026, 04:18 AM
Package URL
pkg:socket/skills-sh/openlark%2Fskills%2Fsocial-auto-publisher%2F@878ce67a7b03cd0711e345a2b4f52e73792414b719af88abfd3c09908711348f
Security Audit — socket — social-auto-publisher