last30days

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/lib/vendor/bird-search/lib/cookies.js

This module is not overtly malware by itself (no execution of untrusted code beyond a normal dependency import, and no direct exfiltration/network calls are present). However, it performs high-sensitivity credential extraction by targeting x.com auth cookies (auth_token and ct0) from env/CLI and optionally from local browser profiles, then returns a reusable Cookie header to the caller. The main security concerns are (1) credential-handling risk due to returning session secrets and (2) supply-chain trust in the dynamically imported cookie-access dependency.

Confidence: 66%Severity: 64%
Audit Metadata
Analyzed At
Apr 26, 2026, 01:53 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Flast30days-skill%2Flast30days%2F@87ada1a1aef352aecf0586a01738ca162b6e5526