twitter-thread-creation

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill aims to generate and post Twitter/X threads via a CLI, which is coherent with its stated purpose. However, it relies on a remote curl|bash download to install a binary from an unverifiable source, coupled with a checksum file, introducing a significant supply-chain and execution risk. The data flow for credentials is underspecified; if credentials are passed to the downloaded binary, this becomes a credential-exposure risk. Given the presence of an unquestioned download-execute pattern and unverifiable binary, this skill should be classified as suspicious until a verifiable, signed distribution path (e.g., official package registry, verifiable source, and explicit credential handling) is provided. Overall risk: suspicious.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Ftwitter-thread-creation%2F@17787322757adecc638de641815cc824b0bc9b82