direct-messages

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Functionally, the package matches its stated purpose: it provides client-side tools (console scripts) to bulk-send and manage DMs on X. There is no explicit evidence in the provided fragment of built-in remote exfiltration, hard-coded credentials, or obfuscation. The main risks arise from the distribution/execution method (paste-into-console), the high privileges granted by acting in the user's authenticated session (read and send private messages), and client-side persistence (localStorage) that exposes metadata. Treat this as a medium security risk: safe if audited and run by a knowledgeable operator in a controlled environment, but dangerous if used blindly or after modification. Apply strict operational controls (audit code before paste, use dryRun, remove persisted data, avoid exports) and avoid running on high-value accounts without review.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 28, 2026, 09:54 AM
Package URL
pkg:socket/skills-sh/nirholas%2FXActions%2Fdirect-messages%2F@e4d346cdc789bd5fd853c80dc08e2cfe1414f8d9