X/Twitter Research

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed X/Twitter research helper that uses a twitterapi.io API key to fetch public posts and save local trend reports.

Install only if you intend to let the agent use your twitterapi.io API key and consume provider quota. Use a dedicated key if possible, keep the secret file private, control any repeated runs yourself, and treat generated reports containing social-media text as untrusted research material.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs loading a locally stored API key from a secrets file and using it in outbound requests, but provides no warning about credential sensitivity, third-party data transfer, or limits on when network access is appropriate. In an agent setting, this can normalize automatic use of local secrets and transmit authenticated requests to an external service without explicit user consent or review.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal