opentwitter

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's basic capability matches its purpose, and its install footprint is small, but it routes all Twitter-related access and the required bearer token through a third-party 6551 service rather than official X APIs. The biggest concerns are credential forwarding to an intermediary, token-in-query-string for WebSocket auth, and remote state-changing watchlist actions; this is more a third-party trust and data-flow risk than confirmed malware.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
Apr 13, 2026, 10:55 AM
Package URL
pkg:socket/skills-sh/6551Team%2Fopentwitter-mcp%2Fopentwitter%2F@07ca1a4282d1330711515902c185ed434afdff91