twitter-automation

Fail

Audited by Socket on Mar 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill’s purpose matches social-media automation, but its footprint is high risk: it installs a remote same-org CLI via pipe-to-shell, routes X credentials and actions through inference.sh infrastructure instead of direct official API usage, enables autonomous posting/DM/follow actions, and encourages transitive skill installation. This is not confirmed malware, but it is a high-risk agent skill with third-party credential/action mediation.

Confidence: 85%Severity: 84%
Audit Metadata
Analyzed At
Mar 27, 2026, 02:29 PM
Package URL
pkg:socket/skills-sh/inference-sh-8%2Fskills%2Ftwitter-automation%2F@987be7d5bca7cc744fc86cd0f1ce63e3e6cc1edd