bird

Warn

Audited by Socket on Mar 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The bird skill presents a plausible CLI for interacting with X/Twitter using cookies or an external Sweetistics API, but it exhibits notable security concerns: credential exposure via browser cookies, installation via a third-party brew tap, and potential data routing through an external API. These factors make the capability align with its stated purpose but with elevated risk and nontrivial surface for credential leakage and supply-chain issues. Overall, the design is Suspicious rather than Benign, requiring careful source verification, explicit user consent for cookie usage, and verified, auditable installation sources before deeming it safe for broader use.

Confidence: 65%Severity: 55%
Audit Metadata
Analyzed At
Mar 8, 2026, 05:27 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fbird%2F@aabf7cd860042a384603e0663fb5dc7d03fea1fb