agentbox-twitter

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated Twitter research purpose, and its runtime dependency appears to be from the OpenClaw ecosystem rather than an obviously rogue binary. The main concern is data-flow and action scope: all requests go through an AgentBox-operated paid gateway instead of official X/Twitter APIs, and each call can trigger automatic USDC micropayments. That makes the skill higher risk than a normal documentation or API wrapper skill, though not clearly malicious from the provided evidence.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 02:20 PM
Package URL
pkg:socket/skills-sh/cascade-protocol%2Fagentbox%2Fagentbox-twitter%2F@a5d3ee3a87affd50c32debeab9c56a7245d3579a