social-publisher
Fail
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The Social Publisher skill appears to be a coherent, purpose-aligned automation tool for multi-platform publishing with scheduling, caption optimization, and analytics. It leverages standard cloud services and APIs; however, it involves multiple external integrations and data flows that could expose tokens or credentials if not properly protected. The overall threat level is low-to-moderate (benign with notable credential/data flow considerations). Proper secret management (secure vaults, scoped API tokens, audit logging) and explicit per-action user approvals for publishing would strengthen security posture.
Confidence: 98%
Audit Metadata