tiktok-post

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent and uses same-org Publora endpoints, so it does not look malicious. However, it grants a third-party remote MCP server a persistent API key and the ability to perform autonomous public posting on TikTok, which creates meaningful security and real-world action risk beyond a low-risk documentation skill.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Apr 2, 2026, 12:51 PM
Package URL
pkg:socket/skills-sh/publora%2Fskills%2Ftiktok-post%2F@e26334f7f6a12a5fc9f9d5ec25714bacbbf382e6