twitter

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose matches social posting, but the implementation footprint is not fully trustworthy because it relies on an unspecified external `twitter` CLI with unverifiable provenance and undocumented data flow. The skill also enables autonomous public posting, so risk is high even without confirmed malicious intent.

Confidence: 86%Severity: 83%
Audit Metadata
Analyzed At
Mar 18, 2026, 08:05 AM
Package URL
pkg:socket/skills-sh/Blave-TW%2Fblave-quant-skill%2Ftwitter%2F@04412fc58e2b8bab11c9c57578ed84414b45f2e4