growth-automation

Fail

Audited by Socket on Feb 28, 2026

2 alerts found:

Obfuscated FileSecurity
Obfuscated FileHIGH
references/supporting-scripts.md

No definitive evidence of classic malware in the described files (no reverse shell, cryptominer, or explicit exfiltration to attacker domains is described). However, the package purpose and features introduce meaningful security and abuse risks: credential leakage from multi-account management, privacy violations from scraping and exporting user data, and operational evasion designed to bypass platform rate limits or detection. Treat this codebase as high-risk from an abuse and data-protection perspective and require a thorough code-level audit focused on credential handling, external endpoints, dynamic code execution, and exported data sanitization before deployment.

Confidence: 98%
SecurityMEDIUM
SKILL.md

The fragment is technically benign in isolation with respect to code-level security risks (no secrets or external data transfers shown). It describes a legitimate-but-risky automation toolkit for social growth via browser interactions. Primary concerns are platform policy/abuse risk and user consent/privacy implications, not intrinsic malware or data exfiltration.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 09:55 AM
Package URL
pkg:socket/skills-sh/nirholas%2FXActions%2Fgrowth-automation%2F@dccd06137aa6168d9fab3ae5523ec95ced60fc1c