baoyu-danger-x-to-markdown

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill aligns with its stated purpose of converting X content to Markdown with consent-managed access, but it introduces notable security and privacy risks due to: reliance on reverse-engineered APIs with consent prompts, handling of user credentials/tokens, browser cookie automation, and use of unverifiable external tooling. The data flow includes potential exfiltration vectors through credentials and automated browser actions, and the dependency surface includes non-official binaries. While not inherently malicious, the footprint is high-risk and warrants careful review of credential handling, sourcing of dependencies, and explicit user consent scopes. Treat as SUSPICIOUS with a leaning toward BENIGN only if all credential safeguards, explicit per-action user prompts, and verifiable dependencies are rigorously enforced.

Confidence: 70%
Audit Metadata
Analyzed At
Mar 12, 2026, 07:52 AM
Package URL
pkg:socket/skills-sh/ideacco%2Fbaoyu-skills-openclaw%2Fbaoyu-danger-x-to-markdown%2F@8c4f37c615ec30aa7a0ae1f6a40bcbae30dd9a82