xbird

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
skills/xbird/SKILL.md

SUSPICIOUS: the skill’s Twitter capabilities match its stated purpose, but its trust model is weak. The main concerns are raw browser/session cookie access, forwarding those cookies to an externally executed npm package, automatic wallet creation, and incomplete publisher verification between the skill repo and package scope. This is not confirmed malware, but it carries meaningful credential and account-action risk.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:40 PM
Package URL
pkg:socket/skills-sh/checkra1neth%2Fxbird-skill%2Fxbird%2F@24334733f267e75b97fe80c45b80c4ed4db37893