twitterapi-io

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent and read-only, but it requires installing a GitHub-hosted CLI of unclear provenance and then handing that CLI the twitterapi.io API key. Because the binary/tool source is not verified as an official same-org distribution path and it receives credentials, the install-trust and credential-forwarding risks dominate.

Confidence: 88%Severity: 84%
Audit Metadata
Analyzed At
Mar 15, 2026, 11:53 PM
Package URL
pkg:socket/skills-sh/ropl-btc%2Ftwitterapi-io-cli%2Ftwitterapi-io%2F@481e2325fb1a9b73ac161f9434799ba8e834dd0d