pinch-to-post

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated WordPress automation purpose mostly matches the visible REST/WP-CLI capabilities, and the documented network flow to official WordPress endpoints is coherent. However, major advertised features depend on missing executable helpers (especially ./wp-rest.sh and social posting functions) that are unverifiable black boxes and likely receive credentials, making the skill high risk despite an otherwise plausible purpose.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Mar 21, 2026, 01:02 PM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fpinch-to-post%2F@03a931c3d852a73cfe5c01fbb97410221ab24654