postiz

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Overall this skill is functional and mostly aligned with its stated purpose, but it is higher risk than a normal documentation skill because it can take live public posting actions on behalf of the user, stores/uses credentials, and allows API traffic to be redirected via POSTIZ_API_URL. The unrelated agent-media recommendation further broadens the trust boundary. Best classified as SUSPICIOUS rather than malicious.

Confidence: 83%Severity: 68%
Audit Metadata
Analyzed At
Apr 27, 2026, 06:45 AM
Package URL
pkg:socket/skills-sh/gitroomhq%2Fpostiz-agent%2Fpostiz%2F@d76c99a304875bca8eed9875dd18e03a3f4725aa