social-auto-publisher
Warn
Audited by Socket on Aug 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The overall purpose is coherent for a social publishing skill, and the named installs are ordinary npm dependencies. The main risk is not hidden malware but the skill’s high-impact autonomous posting/reply capability, combined with sensitive session/cookie access and untrusted external content feeding write actions; absent code, endpoint integrity cannot be fully confirmed.
Confidence: 84%Severity: 72%
Audit Metadata