novita-social-monitor

Fail

Audited by Socket on Mar 2, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The fragment is an automation spec for monitoring a Twitter/X following list and keeping a last-check state. It is not directly malicious: there are no hardcoded secrets, obfuscated payloads, or explicit exfiltration endpoints in the provided text. The main security concerns are supply-chain risk (delegation to an external twitterapi CLI that will handle credentials and network traffic), privacy/surveillance potential from automated scraping, and a fragile state-file write pattern that could be abused or corrupted. Operators should audit and pin the twitterapi-cli, secure token handling, add input validation and safer file I/O, and consider privacy and rate-limiting controls before use.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 2, 2026, 01:40 PM
Package URL
pkg:socket/skills-sh/jaxzhang-svg%2Fnovita-skills%2Fnovita-social-monitor%2F@89e951d694438f3a858557c61dc6793b11164035