social-push
Audited by Socket on Mar 11, 2026
1 alert found:
Obfuscated FileThe skill presents a coherent and proportionate footprint for a social posting helper: it uses browser automation to draft posts and explicitly guards against automatic publishing, requiring user confirmation. Data flows are largely user-initiated and platform-bound, with drafts stored within the platform context via the authenticated browser session. There are no evident unverifiable binaries or credential harvest patterns. Minor concerns include reliance on browser session data for authentication and potential data exposure during multi-platform workflows; these are manageable with strict session control and clear user consent. Overall, the risk posture is low-to-moderate and aligned with the stated purpose.