x-twitter-reader
Warn
Audited by Socket on Aug 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent, and the use of uv plus a pinned PyPI package is comparatively disciplined, but the skill’s core operation depends on a non-official third-party CLI that may reuse X session cookies or auth tokens. That credential forwarding, combined with optional third-party Jina routing, makes the skill higher risk than a normal documentation or API-integration skill even though it is not confirmed malware.
Confidence: 89%Severity: 81%
Audit Metadata