storyclaw-x-manager

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities broadly match its stated purpose, and the visible data flow appears aimed at official X APIs rather than a proxy. However, it stores raw per-user credentials in local JSON files and enables autonomous public actions (including auto-replies), which is disproportionate for an agent skill unless tightly user-gated. No malicious exfiltration or supply-chain behavior is shown in the provided text, but the unreviewed local scripts and automation features create meaningful security risk.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:21 AM
Package URL
pkg:socket/skills-sh/storyclaw-official%2Ftalenthub%2Fstoryclaw-x-manager%2F@4891fee2f9a9a75342d54fb94e1844f86d1105dd