twinmind-core-workflow-b

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s overall purpose is coherent, but it combines unverified TwinMind API claims, generic token use, broad npm execution rights, and autonomous outbound actions (email/task creation). This looks more like a risky workflow automation skill than confirmed malware: no clear exfiltration endpoint or deceptive installer is present, but the permissions and real-world actions are broader and less controlled than the documentation justifies.

Confidence: 81%Severity: 68%
Audit Metadata
Analyzed At
Apr 4, 2026, 07:28 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus%2Ftwinmind-core-workflow-b%2F@7c2370c8a18cad6dacd9e3cbbc4fe6c18822db32