bluesky-post

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's core function is coherent, and the endpoints appear to be official Publora services, so this is not a fake installer or obvious malware. However, it requires routing Bluesky activity through Publora, including forwarding a Bluesky app password to a third party and giving an AI agent the ability to schedule/publicly post; combined with a plan-doc inconsistency, this makes the skill medium/high risk rather than benign.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Apr 2, 2026, 12:51 PM
Package URL
pkg:socket/skills-sh/publora%2Fskills%2Fbluesky-post%2F@bf458bade0054474c0605dde1513567abdc39237