twitter-cli

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose matches Twitter operations and the install path is relatively normal, but its core auth design depends on extracting local browser cookies and handing them to an external CLI. That credential handling is high-trust and risky for an agent skill, especially alongside account-writing capabilities, though there is no clear evidence of outright malware or off-platform exfiltration.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 18, 2026, 06:33 AM
Package URL
pkg:socket/skills-sh/MidnightV1%2FClaude-Code-Feishu%2Ftwitter-cli%2F@e4f5bbeaab7ffce129f4ca6f8092a400e0e837b4