x-mastery
Audited by Socket on Feb 16, 2026
1 alert found:
Malware[Skill Scanner] Natural language instruction to download and install from URL detected The skill fragment is conceptually aligned with its stated purpose as an algorithm/engagement guide. The primary risk stems from an external, unknown installation source (clawdhub) that could introduce malicious code or supply-chain vulnerabilities. No hardcoded secrets or data exfiltration appear in the text itself. Treat the installation line as suspicious and verify provenance before executing. LLM verification: The provided artifact is a static instructional guide about optimizing content for X (Twitter). There is no executable code or direct technical backdoor in the text itself. The primary supply-chain concern is an unqualified installer line ('install lxgicstudios/x-mastery') that instructs users to fetch external content; that external content must be audited before execution. The guide contains authoritative-sounding algorithmic weights without citations and recommends high-volume interaction pat