A real-time intelligence feed tracking the top 50 AI organizations and influencers globally.
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The skill bundle exhibits high-risk behavior by accessing sensitive local data. Specifically, `scripts/x-scraper-free.js` uses `scraper.useCookiesFromBrowser('chrome')` to extract session cookies from the user's browser to bypass X/Twitter API restrictions. While this aligns with the stated 'free scraping' functionality, it is a significant privacy risk. Additionally, `scripts/x-monitor.js` contains a hardcoded X API key (THp2c1V4bW5JQVJ1S09IY1BzN1NubDoxaXJpUQ), which constitutes a credential leak. There is no clear evidence of intentional exfiltration of the stolen cookies to a third-party server, placing it in the suspicious category rather than malicious.
