write-blog
Warn
Audited by Socket on Aug 6, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: mostly coherent as a blog-authoring skill, with no explicit credential harvesting or remote installer behavior, but it has medium risk because it combines broad local write+Bash access with optional environment-defined slash commands and a possible public-posting step. The core workflow is proportionate; the main uncertainty is where `/humanizer`, `/direct-response-copy`, and especially `/x-tweet` send data and whether posting occurs without explicit per-action confirmation.
Confidence: 84%Severity: 58%
Audit Metadata