social-sbti

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core workflow is coherent for a social-media personality-card skill, but trust is weakened by unseen Python dependencies and by forwarding X credentials/session data to an unofficial third-party client (Twikit). No direct malware or clear exfiltration endpoint is shown, yet the privacy-sensitive purpose and third-party credential handling make this a medium-to-high security risk skill.

Confidence: 82%Severity: 64%
Audit Metadata
Analyzed At
Apr 10, 2026, 08:27 AM
Package URL
pkg:socket/skills-sh/Backtthefuture%2Fhuangshu%2Fsocial-sbti%2F@19d5206cf1cb17fd365f8044ee30d1b3ec6e69b9