hn-to-x-poster

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is coherent with its stated purpose and uses official first-party sites plus an apparently official browser-control tool, so it is not credential-harvesting malware. However, it enables automatic public posting from an already logged-in social account after consuming untrusted web content, which is a high-risk autonomous action for an AI agent even without obvious exfiltration.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Mar 15, 2026, 01:19 PM
Package URL
pkg:socket/skills-sh/hexbee%2Fhello-skills%2Fhn-to-x-poster%2F@ef2c40b4e0c1f1df4462bd46bfadb318d42caee9