engagement-tracker
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's analytics purpose is plausible, and most data flows go to official Reddit/X services, but it relies on browser-session scraping and a user-specified local Twikit environment with no provenance controls. Because it forwards Twitter/X session cookies to third-party local code that the skill does not verify, the overall risk is high even without clear evidence of intentional exfiltration.
Confidence: 87%Severity: 82%
Audit Metadata