xactions-mcp-server

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The package's design and documentation create a high-risk operational profile: it instructs users to supply a raw X session cookie and executes code fetched at runtime (npx), while offering full account capabilities (read DMs, post, follow/unfollow, export data). This is an unsafe pattern for casual or untrusted use. While the README/manifest alone does not prove active malicious code, the combination of credential harvesting pattern, lack of explicit authentication best practices, and supply-chain execution model merits treating the package as high risk. Do not supply your session cookie to this tool without a full code and dependency audit, strong network controls, and preferably an audited OAuth-based alternative.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 09:55 AM
Package URL
pkg:socket/skills-sh/nirholas%2FXActions%2Fxactions-mcp-server%2F@129c3d77187ba22431205b80d05373eaca6ea2e4