xitter

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and credential scope are mostly aligned with an X/Twitter integration, and data flow appears aimed at official X API usage. Risk comes from installing an unpinned third-party CLI directly from GitHub, storing full write-capable credentials in a local .env file, and enabling autonomous public posting actions. This is not confirmed malware, but it is a medium-risk skill with notable supply-chain and account-action concerns.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 4, 2026, 05:53 PM
Package URL
pkg:socket/skills-sh/NousResearch%2Fhermes-agent%2Fxitter%2F@2cbc95f2a8d7a2269463b6edbf4e33999c727396