twitter-automation

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches the social automation capabilities, but the skill’s footprint is high-risk because it enables autonomous posting/DM/follow actions and routes access through a third-party CLI/platform instead of direct X APIs. Install provenance is same-org and partially verifiable, so this is not confirmed malicious, but the combination of external CLI trust, mediated credentials, and transitive skill installation makes it a high-risk automation skill.

Confidence: 85%Severity: 73%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:30 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fagent-skills-registry%2Ftwitter-automation%2F@987be7d5bca7cc744fc86cd0f1ce63e3e6cc1edd