twitter-automation

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's capabilities match its stated Twitter/X automation purpose, but it relies on transitive skill installation, vendor-controlled CLI/install paths, and routes actions/auth through inference.sh rather than directly to X. That is coherent for the product, not confirmed malware, but it creates meaningful trust and autonomy risk disproportionate to a simple API wrapper.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Sep 19, 2026, 10:24 AM
Package URL
pkg:socket/skills-sh/inference-sh%2Fskills%2Ftwitter-automation%2F@215fa28b5f5231315d698f4134eca23c9a5779c635c0eb4a6b0651da0142a604
Security Audit — socket — twitter-automation