twitter-reader
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The overall purpose is coherent for a Twitter/X reader, but the implementation footprint leans on unofficial intermediaries and an unspecified third-party CLI auto-install. That is disproportionate for a read-only content fetcher and weakens install trust and data-flow integrity, especially if `twitter-cli` uses browser cookies or other auth context. No confirmed malware or exfiltration behavior is shown, but the skill should not be treated as benign until the CLI install path, version pinning, and credential/data routing are clarified.
Confidence: 87%Severity: 58%
Audit Metadata