Back to plugin

Security audit

Twitter

Security checks across malware telemetry and agentic risk

Overview

The package appears to implement a Twitter/X client that talks to AIsa relay endpoints and requires a single AISA_API_KEY; its files, instructions, and requested credential are largely coherent with the stated purpose, though there are small metadata inconsistencies you should verify before installing.

This package implements a Twitter/X client that forwards requests to AIsa's relay (api.aisa.one) and requires an AISA_API_KEY. Before installing: (1) Confirm you trust the AIsa service (api.aisa.one) since all posting/engagement flows go through it. (2) Provide only the AISA_API_KEY (do not share Twitter passwords or cookie data). (3) Note the registry metadata in the listing omitted the AISA_API_KEY requirement — rely on the plugin manifest and SKILL.md for accurate runtime requirements. (4) If you need to audit network endpoints, review the bundled Python scripts (they are present in the package) and consider pinning or overriding TWITTER_RELAY_BASE_URL to an endpoint you control if appropriate. (5) Remember autonomous invocation is allowed by default; if you need to restrict automatic posting, adjust agent/plugin permissions or require explicit user confirmation before posting.

VirusTotal

No VirusTotal findings

View on VirusTotal

Static analysis

No suspicious patterns detected.