last30days

Warn

Audited by Socket on May 20, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/lib/vendor/bird-search/lib/cookies.js

This module is not overtly malware by itself (no execution of untrusted code beyond a normal dependency import, and no direct exfiltration/network calls are present). However, it performs high-sensitivity credential extraction by targeting x.com auth cookies (auth_token and ct0) from env/CLI and optionally from local browser profiles, then returns a reusable Cookie header to the caller. The main security concerns are (1) credential-handling risk due to returning session secrets and (2) supply-chain trust in the dynamically imported cookie-access dependency.

Confidence: 66%Severity: 64%
Audit Metadata
Analyzed At
May 20, 2026, 12:20 PM
Package URL
pkg:socket/skills-sh/Sebfranklin%2Ffranklin-skills%2Flast30days%2F@6030e7db728cbf1f1d8c992046faadd724a851ed
Security Audit — socket — last30days