NYC

x-report-generator

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected Based on the provided skill manifest and README-like description, the project is consistent with a Playwright-based X/Twitter scraper that analyzes and exports reports. There are no explicit signs of malicious code or obfuscation in this text. The primary security concerns are proper handling of cookies/session tokens (credential exposure risk), possible loading of third-party assets in generated HTML, and legal/TOS issues from scraping. To fully rule out exfiltration or other malicious behavior, the actual scripts (scripts/x_report_generator.py and any modules it uses) must be inspected for network calls to non-official domains, logging of secrets, or code that transmits cookies/data to third parties. Recommend code review focusing on cookie handling, network endpoints, and any analytics/telemetry in the report templates. LLM verification: The provided SKILL.md documents a Playwright-based X/Twitter scraping/reporting tool whose declared behavior matches the permissions it requests (cookies, Playwright/browser, filesystem). There is no explicit evidence of malware, backdoors, or obfuscated malicious code within this documentation. However, the package presents moderate security concerns: saving and reusing cookies.json (sensitive session tokens) without secure-storage guidance; unpinned dependency instructions that increase supply

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 02:30 AM
Package URL
pkg:socket/skills-sh/aidotnet%2Fmoyucode%2Fx-report-generator%2F@52afc40ad88de6b35debc4e1b8654801c11824d2