storyclaw-x-manager
Warn
Audited by Socket on Mar 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s capabilities broadly match its stated purpose, and the visible data flow appears aimed at official X APIs rather than a proxy. However, it stores raw per-user credentials in local JSON files and enables autonomous public actions (including auto-replies), which is disproportionate for an agent skill unless tightly user-gated. No malicious exfiltration or supply-chain behavior is shown in the provided text, but the unreviewed local scripts and automation features create meaningful security risk.
Confidence: 85%Severity: 68%
Audit Metadata