twitter-automation

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill's capabilities match its stated Twitter automation purpose, but it enables high-impact autonomous account actions, routes operations through a third-party platform/CLI, and promotes transitive skill installation. The same-org installer reduces signs of outright maliciousness, yet the combination of remote installer trust, credential forwarding, and public-action automation makes this a high-risk skill to grant to an agent.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:35 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fagent-skills%2Ftwitter-automation%2F@987be7d5bca7cc744fc86cd0f1ce63e3e6cc1edd