twitter-hand-skill

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
HAND.toml

The fragment describes a legitimate but highly privileged Twitter/X automation agent. It accesses a bearer token, reads external content, persists account data, and can publish tweets, replies, and likes. The shown code contains no clear malware indicators or obfuscation, but direct posting when approval_mode is disabled creates meaningful account, privacy, and unauthorized-action risk. Review access controls, token handling, API scopes, generated-content validation, and the unseen portions of the file.

Confidence: 94%Severity: 56%
Audit Metadata
Analyzed At
Sep 19, 2026, 06:42 PM
Package URL
pkg:socket/skills-sh/rightnow-ai%2Fopenfang%2Ftwitter-hand-skill%2F@d6aefa9d9dcbe98dd9b861105d28390796ed279f1e6cbc964ecfefba7befac47