twitter-automation

Warn

Audited by Socket on Aug 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s capabilities match its stated Twitter/X automation purpose, but it relies on transitive remote skill installation and an external CLI that mediates authentication and account actions through inference.sh. The main risk is not hidden malware signals; it is the combination of supply-chain trust, credential forwarding to third-party tooling, and autonomous public-action capability.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Aug 6, 2026, 05:03 AM
Package URL
pkg:socket/skills-sh/whytryharder%2Fskills%2Ftwitter-automation%2F@730ab5370b839e0e339d5e7894fd8c414380529be3c42f63983e0fa6f0789061
Security Audit — socket — twitter-automation