bird

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated Twitter/X purpose, but it instructs the agent to install an unverified standalone binary and then use browser-derived auth cookies through that binary for authenticated actions. That creates a significant supply-chain and credential-forwarding risk even without evidence of confirmed malware.

Confidence: 87%Severity: 86%
Audit Metadata
Analyzed At
Mar 17, 2026, 09:39 AM
Package URL
pkg:socket/skills-sh/zaydiscold%2Fbird-skill%2Fbird%2F@eb4d985c8f5396bb165d08a3f485ac721be398cf