xurl

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill documentation describes a CLI that legitimately requires Twitter/X API credentials and performs account-level actions. The requested capabilities and credentials are consistent with the stated purpose. No direct malicious behavior, obfuscated code, or credential-exfiltration patterns are present in the provided doc. The primary risk is supply-chain: the tool is distributed by a third-party publisher (xdevplatform) via Homebrew tap, npm package, and a GitHub Go module. Users should verify the publisher, inspect the source code of the xurl repository before installation, and avoid pasting credentials into untrusted contexts. Overall risk is moderate due to the need to trust the third-party binary with high-privilege API keys.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:14 AM
Package URL
pkg:socket/skills-sh/winsorllc%2Fupgraded-carnival%2Fxurl%2F@41bc6b2bb74cb80a74eb54c26550e159d7a8cf34