autoblogwriter-cli

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The autoblogwriter-cli skill appears largely coherent with its stated purpose of operating a CLI-driven automation of blog ideas/posts/workflows with JSON-centric outputs. The main security considerations are credential handling via environment variables or saved keys and the potential for logs to expose API keys, plus the reliance on an external API endpoint. No evidence of hard-coded untrusted binaries, download/execute patterns, or credential forwarding to third-party code is present. Overall risk is modest (benign-to-suspicious); treat as suspicious primarily due to credential handling and external API exposure until proper secret-management and output masking are confirmed.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 07:31 AM
Package URL
pkg:socket/skills-sh/auto-blog-writer-app%2Fautoblogwriter-skill%2Fautoblogwriter-cli%2F@59ae32a899a9c96af98ae802dee1d8e2d10ae82c