canghe-post-to-x

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The skill is mostly coherent for posting to X, and its main dependency/install path is official Bun infrastructure rather than an unknown third party. However, it intentionally bypasses anti-automation using Chrome CDP, operates with an authenticated browser profile instead of official API auth, and authorizes system-affecting commands like automatic pkill of Chrome debug instances; these make it higher risk than a normal documentation skill but not clearly malicious.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:51 PM
Package URL
pkg:socket/skills-sh/freestylefly%2Fcanghe-skills%2Fcanghe-post-to-x%2F@bac94f8e595acd989320418c1603ad19c7904440