social

Warn

Audited by Socket on Jul 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities broadly match its stated purpose, but it relies on a third-party intermediary CLI/service for all LinkedIn/X access, uses a pipe-to-shell installer, and enables high-impact account actions. This looks more like a coherent but high-trust vendor integration than outright malware; the main risks are supply-chain trust, credential forwarding to third-party code, and autonomous social actions if confirmations are bypassed.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Jul 6, 2026, 11:38 PM
Package URL
pkg:socket/skills-sh/usesocial%2Fskill%2Fsocial%2F@61efb8eb5e326cd4b036d0e612983403990d2de975d7b4f8368e1d5165773045
Security Audit — socket — social