Warn
Audited by Socket on May 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities mostly match its stated Twitter lookup purpose and it shows no malware-like install or exfiltration behavior, but its data flow is not fully direct or transparent: requests and the API key are routed through an unverifiable sc-proxy instead of directly to twitterapi.io’s documented endpoints. That proxy-mediated credential and data path makes the skill medium risk despite otherwise coherent read-only functionality.
Confidence: 85%Severity: 56%
Audit Metadata