retweet

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The capability matches the stated purpose, and there is no malware-style installer or exfiltration pattern. However, the skill performs real public posting through an opaque Shift intermediary rather than directly to X, so users must trust Shift with connected-account actions and token handling. Risk is driven by third-party credential brokering and autonomous public-action potential, not by confirmed malicious behavior.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Mar 13, 2026, 01:26 PM
Package URL
pkg:socket/skills-sh/tryshift-sh%2Fskills-store%2Fretweet%2F@60019ad76a512d0a8b8a95eb074c6a60bbd0cb51