TweetClaw
Security checks across static analysis, malware telemetry, and agentic risk
Overview
TweetClaw appears to be a real X/Twitter automation plugin for Xquik, with credentials and network access that match that purpose.
This looks internally coherent, but it is still a powerful social-media automation tool: if configured, it can post, like, retweet, follow, DM, read private account-related data, and spend Xquik/MPP credits. Install it only if you trust Xquik and the package publisher, keep the API key or MPP signing key secret, review approval prompts for write actions, and avoid changing the base URL unless you intentionally trust that alternative Xquik-compatible server.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings
Risk analysis
No visible risk-analysis findings were reported for this release.
