File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- scripts/xreader.mjs:54
Security audit
Security checks across malware telemetry and agentic risk
This X/Twitter reader skill is purpose-aligned and disclosed, but it requires local X session cookies to work.
Install only if you are comfortable letting this skill use X auth_token and ct0 cookies. Prefer a secondary X account, keep the session file private, and delete ~/.config/xreader/session.json if you no longer want the skill to reuse that account session.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal