x-writer

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The x-writer fragment presents a structured, multi-step instruction set for generating social media posts using predefined formats, voices, and reference materials. There is no evidence of code execution, credential handling, external network calls, or malicious data flows within the provided fragment. The workflow is consistent with its stated purpose (generate posts using reference formats, posts, and voices) and does not exhibit obvious supply-chain risk indicators in isolation. However, the design relies on reading local reference files and an optional founder context, which could be misused if the environment provides spoofed files or if the agent is coerced into skipping steps or disclosing private topics. Overall, the security risk is low to moderate given the current content, but the process requires trustworthy execution environment and integrity of the reference assets to avoid misalignment or leakage of user-provided topic information. The malware score is effectively 0.0 given the current fragment; the security risk score is modest (0.30) due to potential abuse of the multi-step process in contested environments.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 3, 2026, 06:44 PM
Package URL
pkg:socket/skills-sh/owner-rx%2Fownerrx-tools%2Fx-writer%2F@9bfaa070e7314ff05ccf091cbe54836c9ac242d1