twitter-thread-creation

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is largely coherent with its stated purpose of generating and posting Twitter/X threads via a dedicated CLI. However, there are notable supply-chain and credential-handling concerns due to reliance on an external, unverifiable CLI (inference-sh) and indirect data flows through third-party endpoints for media generation. This warrants a suspicious-for-security assessment rather than benign, primarily because the core posting capability depends on an external binary whose integrity and token handling are not demonstrated. Overall, the skill is potentially benign if used in a controlled, trust-validated environment with verified CLI provenance and proper credential management, but it carries meaningful risk given the download/install pattern and third-party data flows.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 09:29 PM
Package URL
pkg:socket/skills-sh/inference-shell%2Fskills%2Ftwitter-thread-creation%2F@f9deae08f8e941ab66954f17f670a3928f466ad4