postey
Warn
Audited by Socket on May 11, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the overall capability matches a social publishing skill, and the API key/file access scope is mostly proportionate. The main concerns are the domain inconsistency in setup instructions, the ability to take autonomous public posting actions, and processing untrusted external video content in a workflow that can lead to publication. No clear evidence of credential harvesting or malicious exfiltration is present, but the trust and autonomy risks are too significant to rate benign.
Confidence: 86%Severity: 63%
Audit Metadata