engagement-tracker

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's analytics purpose is plausible, and most data flows go to official Reddit/X services, but it relies on browser-session scraping and a user-specified local Twikit environment with no provenance controls. Because it forwards Twitter/X session cookies to third-party local code that the skill does not verify, the overall risk is high even without clear evidence of intentional exfiltration.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
Mar 29, 2026, 09:44 AM
Package URL
pkg:socket/skills-sh/PHY041%2Fclaude-agent-skills%2Fengagement-tracker%2F@1564472e572df708fdd4efe9610facd152e66600