x-cdp-scraper

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The tool is clearly designed to accelerate data collection by reusing an authenticated browser session to query Twitter GraphQL APIs and output results locally. While the approach aligns with a data-export workflow, it introduces substantial credential-exposure risks due to CDP-based extraction of cookies/CSRF and the potential for mismanagement of outputs. The data flow from browser state to network to local storage is coherent but demands strong safeguards: redacted logging, least-privilege access, session-scoped tokens, explicit user consent and ToS alignment, and secure storage of outputs. Treat as SUSPICIOUS with high risk unless mitigations are implemented.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 04:35 PM
Package URL
pkg:socket/skills-sh/kohoj%2Fskills%2Fx-cdp-scraper%2F@404431c3ab3609f21d081f4fd401d14a91d9d53c