The skill executes unpinned packages at runtime and routes sensitive authentication credentials through an untrusted third-party platform, creating significant risks of supply chain compromise and credential exfiltration.
npx skills add https://github.com/halt-catch-fire/skillsUnpinned npx package execution — `npx <pkg>` without a version pin pulls latest from npm at runtime (seen 5 times in this file at lines 7, 138, 141, 144, 147)
npx skills
The skill requires a 'belt login' command which routes authentication and API interactions through a third-party platform (inference.sh), potentially exposing Twitter/X credentials or session tokens to an external service. [ensemble: confirmed by 3/3 passes; severity set to the agreed median (ADR-0067).]
belt login
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/halt-catch-fire/skills/twitter-automation)<a href="https://mondoo.com/ai-agent-security/skills/github/halt-catch-fire/skills/twitter-automation"><img src="https://mondoo.com/ai-agent-security/api/badge/github/halt-catch-fire/skills/twitter-automation.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/halt-catch-fire/skills/twitter-automation.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.