Back to skill

Security audit

X/Twitter Automation: 30+ APIs, OAuth Post, One Key

Security checks for vulnerabilities and agentic risk

Overview

The skill’s Twitter/X purpose is coherent, but its posting client can expose the AISA API key in command output and can send credentials and media to an arbitrary HTTP(S) relay if configured that way.

Review before installing. Use this only with an AISA key you are willing to rotate, avoid sensitive search terms or private drafts unless you accept AISA/Twitter processing, require explicit user approval before public posts, and do not run the OAuth client with a custom TWITTER_RELAY_BASE_URL unless it is a trusted HTTPS endpoint.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/twitter_oauth_client.py:337
Finding

AISA API Key Disclosed in CLI JSON Output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/twitter_oauth_client.py:44
Finding

Configurable Plaintext Relay Can Exfiltrate API Credentials and Uploaded Media

Content
View full analysis
str: value = base_url.strip().rstrip("/") if not value: raise RelayConfigError("TWITTER_RELAY_BASE_URL is required.") parsed = urllib.parse.urlparse(value) if parsed.scheme not in {"http", "https"} or not parsed.netloc: raise RelayConfigError("TWITTER_RELAY_BASE_URL must be a valid http(s) URL.") return value ``` ```python def load_config(args: argparse.Namespace) -> Dict[str, Any]: base_url = normalize_base_url( get_env("TWITTER_RELAY_BASE_URL", DEFAULT_BASE_URL) ) aisa_api_key = getattr(args, "aisa_api_key", None) or get_env("AISA_API_KEY") timeout = getattr(args, "timeout", None) or int(get_env("TWITTER_RELAY_TIMEOUT", str(DEFAULT_TIMEOUT))) if not aisa_api_key: raise RelayConfigError("AISA_API_KEY is required.") return { "base_url": base_url, "aisa_api_key": aisa_api_key, "timeout": timeout, } ``` ```python def build_auth_headers(aisa_api_key: str, extra_headers: Optional[Dict[str, str]] = None) -> Dict[str, str]: headers = { "Authorization": f"Bearer {aisa_api_key}", "User-Agent": DEFAULT_CHROME_USER_AGENT, } if extra_headers: headers.update(extra_headers) return headers ``` ```python def post_single_tweet( config: Dict[str, Any], *, content: Optional[str] = None, media_ids: Optional[list[str]] = None, media_files: Optional[list[Dict[str, Any]]] = None, parent_tweet_id: Optional[str] = None, post_type: Optional[str] = None, ) -> Dict[str, Any]: payload: Dict[str, Any] = { "aisa_api_key": config["aisa_api_key"], } if content: pa ...[truncated 3614 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (44)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description presents broad Twitter/X capabilities, but the actual implementation details appear to rely on a third-party relay service and referenced external workflow components not transparently summarized in the main description. This mismatch can mislead users about what data path, trust boundary, and authentication model are actually involved, which is a security-relevant transparency failure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description presents broad Twitter/X capabilities, but the actual implementation details appear to rely on a third-party relay service and referenced external workflow components not transparently summarized in the main description. This mismatch can mislead users about what data path, trust boundary, and authentication model are actually involved, which is a security-relevant transparency failure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README advertises the ability to write and post text and media to Twitter/X but does not clearly warn that user-supplied content will be transmitted to a public third-party platform and may become immediately visible to others. In an agentic context, this omission increases the risk of accidental disclosure, reputational harm, or unintended posting because operators may treat the skill like a read-only data tool unless explicit publication warnings are provided.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares network access and use of an environment secret (AISA_API_KEY) but does not define an explicit permission or allowed-tools scope. That makes its operational boundary unclear to users and host systems, increasing the chance that it is invoked with broader authority than intended and that sensitive queries are transmitted off-platform without clear consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The invocation description is very broad and could cause the skill to trigger on many generic social-media requests. In context, that matters because activation would send user queries to an external third-party API, potentially disclosing sensitive research, monitoring targets, or business context more often than users expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill does not clearly warn users that their queries and target account data are sent to the third-party api.aisa.one service using their API key. This is dangerous because user prompts may contain sensitive competitive intelligence, monitoring targets, or draft content, and the trust boundary is external rather than local.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This endpoint transmits user-supplied query data and the bearer API key to an external third-party service. In this skill's context, external transmission is expected, but it is still security-relevant because the skill encourages broad social listening and monitoring workflows that may include sensitive targets or proprietary investigative intent.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

bash
# Get user info
curl "https://api.aisa.one/apis/v1/twitter/user/info?userName=elonmusk" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Get user profile about (account country, verification, username changes)

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This call sends request parameters and the user's bearer token to api.aisa.one, creating a clear external data-sharing boundary. Although normal for an API client, the skill understates this behavior, so users may not realize that profile/about lookups are performed by a third party rather than locally or directly against Twitter/X.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
-H "Authorization: Bearer $AISA_API_KEY"

# Get user profile about (account country, verification, username changes)
curl "https://api.aisa.one/apis/v1/twitter/user_about?userName=elonmusk" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Batch get user info by IDs

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

Batch user lookups transmit target identifiers and the API credential to an external provider. In a competitive-intelligence or monitoring context, even the set of looked-up accounts can be sensitive business information, so undisclosed transmission increases confidentiality risk.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

md
-H "Authorization: Bearer $AISA_API_KEY"

# Batch get user info by IDs
curl "https://api.aisa.one/apis/v1/twitter/user/batch_info_by_ids?userIds=44196397,123456" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Get user's latest tweets

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

Retrieving recent tweets requires sending the lookup target and bearer token to the external API service. The danger is not the existence of network access itself, but the lack of clear user warning and permission scoping around repeated off-platform monitoring activity.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
-H "Authorization: Bearer $AISA_API_KEY"

# Get user's latest tweets
curl "https://api.aisa.one/apis/v1/twitter/user/last_tweets?userName=elonmusk" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Get user mentions

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

Mention lookups send monitored account details and credentials to a third-party API. In this skill's context, mention monitoring may reveal PR, legal, or incident-response interests, which can itself be sensitive metadata if mishandled or logged externally.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
-H "Authorization: Bearer $AISA_API_KEY"

# Get user mentions
curl "https://api.aisa.one/apis/v1/twitter/user/mentions?userName=elonmusk" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Get user followers

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

Follower queries transmit target accounts and authentication material to an external service. That can expose relationship analysis activity and monitoring priorities, which is sensitive in enterprise intelligence workflows even if the fetched data is nominally public.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
-H "Authorization: Bearer $AISA_API_KEY"

# Get user followers
curl "https://api.aisa.one/apis/v1/twitter/user/followers?userName=elonmusk" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Get user followings

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

Following-list lookups are external transmissions of both query intent and API credentials. Because such queries can reveal strategic research interests or internal investigations, the absence of an explicit warning makes the skill more dangerous than a narrowly scoped client would be.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
-H "Authorization: Bearer $AISA_API_KEY"

# Get user followings
curl "https://api.aisa.one/apis/v1/twitter/user/followings?userName=elonmusk" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Get user verified followers (requires user_id, not userName)

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

Verified-follower analysis sends a specific user ID and credential to an external provider. This is potentially sensitive because it can support profiling or influence analysis, and users are not prominently informed that these queries leave the local environment.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
-H "Authorization: Bearer $AISA_API_KEY"

# Get user verified followers (requires user_id, not userName)
curl "https://api.aisa.one/apis/v1/twitter/user/verifiedFollowers?user_id=44196397" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Check follow relationship between two users

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

Relationship checks between two accounts disclose both monitored identities and the analyst's investigative interest to a third party. In context, this can reveal sensitive diligence or threat-intelligence activity even though the endpoint itself is expected behavior.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
-H "Authorization: Bearer $AISA_API_KEY"

# Check follow relationship between two users
curl "https://api.aisa.one/apis/v1/twitter/user/check_follow_relationship?source_user_name=elonmusk&target_user_name=BillGates" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Search users by keyword

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

User-search queries may contain sensitive research terms, and the request sends those terms plus the API key to an external API. The security issue is the undisclosed third-party transmission of free-form user input, which may include confidential project names or watchlist themes.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

-H "Authorization: Bearer $AISA_API_KEY"

Search users by keyword

curl "https://api.aisa.one/apis/v1/twitter/user/search?query=AI+researcher"
-H "Authorization: Bearer $AISA_API_KEY"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

Advanced tweet search transmits free-form search content and the bearer token to a third-party service. In this skill context, social-listening searches are especially likely to include sensitive company, product, or incident terms, making undisclosed external transmission materially risky.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

bash
# Advanced tweet search (queryType is required: Latest or Top)
curl "https://api.aisa.one/apis/v1/twitter/tweet/advanced_search?query=AI+agents&queryType=Latest" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Search top tweets

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

Top-search queries share user-entered terms and credentials with the external provider. This is routine API usage, but it still constitutes a confidentiality risk when the skill description does not foreground that social listening content is processed by a third party.

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

md
-H "Authorization: Bearer $AISA_API_KEY"

# Search top tweets
curl "https://api.aisa.one/apis/v1/twitter/tweet/advanced_search?query=AI+agents&queryType=Top" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Get tweets by IDs (comma-separated)

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

Tweet-ID retrieval sends looked-up identifiers and the API key to an external service. Even when IDs are public, the selection of which tweets are being investigated can be sensitive investigative metadata, particularly in compliance or incident contexts.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
-H "Authorization: Bearer $AISA_API_KEY"

# Get tweets by IDs (comma-separated)
curl "https://api.aisa.one/apis/v1/twitter/tweets?tweet_ids=1895096451033985024" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Get tweet replies

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

Reply-thread retrieval transmits the focal tweet ID and credential to a third party. In context, conversation analysis can reveal what controversies, incidents, or campaigns a user is examining, so lack of disclosure heightens the privacy risk.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
-H "Authorization: Bearer $AISA_API_KEY"

# Get tweet replies
curl "https://api.aisa.one/apis/v1/twitter/tweet/replies?tweetId=1895096451033985024" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Get tweet quotes

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

Quote retrieval sends the investigated tweet ID externally along with the bearer token. This can expose sensitive monitoring interest patterns to the provider even if the underlying content is public.

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
-H "Authorization: Bearer $AISA_API_KEY"

# Get tweet quotes
curl "https://api.aisa.one/apis/v1/twitter/tweet/quotes?tweetId=1895096451033985024" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Get tweet retweeters

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

Retweeter analysis shares the queried tweet ID and credential with an external service. In enterprise social-intelligence use, this may expose campaign-tracking or influence-analysis targets, which are sensitive even though the endpoint is functionally expected.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
-H "Authorization: Bearer $AISA_API_KEY"

# Get tweet retweeters
curl "https://api.aisa.one/apis/v1/twitter/tweet/retweeters?tweetId=1895096451033985024" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Get tweet thread context (full conversation thread)

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

Thread-context retrieval transmits the target tweet and API key to the external API. This reveals conversational targets and potentially sensitive investigative focus to the provider, making transparency and permission scoping important.

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
-H "Authorization: Bearer $AISA_API_KEY"

# Get tweet thread context (full conversation thread)
curl "https://api.aisa.one/apis/v1/twitter/tweet/thread_context?tweetId=1895096451033985024" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Get article by tweet ID

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

Article retrieval by tweet ID is another external transmission of request intent and credentials. While expected for a remote API client, it is still a true security concern because the skill does not prominently tell users that all such lookups are mediated by AISA.

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

-H "Authorization: Bearer $AISA_API_KEY"

Get article by tweet ID

curl "https://api.aisa.one/apis/v1/twitter/article?tweet_id=1895096451033985024"
-H "Authorization: Bearer $AISA_API_KEY"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

Trend lookups send request metadata and the API key to a third party. This is lower sensitivity than free-form search, but it still represents undisclosed off-platform processing and should be treated as a real data-transfer risk.

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

bash
# Get trending topics (worldwide)
curl "https://api.aisa.one/apis/v1/twitter/trends?woeid=1" \
  -H "Authorization: Bearer $AISA_API_KEY"

# Get list members

Static analysis

No suspicious patterns detected.