x-mastery

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Natural language instruction to download and install from URL detected The skill fragment is conceptually aligned with its stated purpose as an algorithm/engagement guide. The primary risk stems from an external, unknown installation source (clawdhub) that could introduce malicious code or supply-chain vulnerabilities. No hardcoded secrets or data exfiltration appear in the text itself. Treat the installation line as suspicious and verify provenance before executing. LLM verification: The provided artifact is a static instructional guide about optimizing content for X (Twitter). There is no executable code or direct technical backdoor in the text itself. The primary supply-chain concern is an unqualified installer line ('install lxgicstudios/x-mastery') that instructs users to fetch external content; that external content must be audited before execution. The guide contains authoritative-sounding algorithmic weights without citations and recommends high-volume interaction pat

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 11:06 PM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fx-mastery%2F@6ec1afd218f164d0d7734efd063d336e531d5690