Back to skill

Security audit

Xint Rs

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real X/Twitter intelligence CLI, but it needs Review because its installer and some account/cloud capabilities are broader and less safely scoped than the skill description suggests.

Review this before installing. Prefer building from a reviewed source tag or using a trusted package manager instead of the curl-to-bash installer. Keep the CLI in read_only policy unless you intentionally want account mutations, and do not run OAuth setup unless you are comfortable granting broad X scopes including write permissions. Treat collections, bookmark KB sync, package API features, and webhooks as remote data-sharing paths and use only endpoints you control.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:32
Finding

Mutable Remote Installer Is Piped Directly Into a Shell

Content
View full analysis
\ curl -fsSL https://raw.githubusercontent.com/0xNyk/xint-rs/main/install.sh | bash ``` ``` ### Technical Analysis The documented installation procedure retrieves `install.sh` from the mutable `main` branch of a personal GitHub repository and pipes the response directly into `bash`. The user has no opportunity to inspect the retrieved script, and the command does not authenticate the script using a pinned digest or cryptographic signature. Although HTTPS protects the connection in transit under normal conditions, it does not protect against compromise of the repository, maintainer account, release workflow, or mutable branch. The effective code executed by this command can change after the Skill package has been audited. The purported pinned-version example only controls the release version selected by the downloaded installer; the installer itself is still retrieved from the mutable `main` branch. Consequently, pinning the release tag does not pin or authenticate the shell code initially executed. This installation mechanism is not necessary for the Skill’s X/Twitter intelligence functionality. A package-manager installation, source build from a reviewed commit, or separately downloaded and verified release artifact would provide the required functionality without immediately executing mutable remote shell content. ### Attack Path 1. An attacker compromises the GitHub maintainer account, repository, branch protection, or CI release credentials. 2. The attacker modifies `main/install.sh` to include arbitrary shell commands. 3. A user follows the installation command in `README.md`. ...[truncated 992 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
install.sh:106
Finding

Installer Accepts Downloaded Executables When Integrity Verification Is Unavailable

Content
View full analysis
&2 exit 1 fi echo "==> No checksums asset found; skipping checksum verification" return fi local expected expected="$(awk -v name="$asset_name" '$0 ~ name {print $1; exit}' "$checksums_file" || true)" if [[ -z "$expected" ]]; then if [[ "$REQUIRE_CHECKSUM" == "1" ]]; then echo "error: checksum required but asset entry not found in checksums file" >&2 exit 1 fi echo "==> Checksums file present, but no entry for $asset_name; skipping verification" return fi ``` The downloaded executable is subsequently accepted and installed: ```bash main() { require_cmd curl require_cmd python3 read -r os arch <<<"$(detect_platform)" local tmpdir tmpdir="$(mktemp -d)" trap 'rm -rf "$tmpdir"' EXIT local release_json="${tmpdir}/release.json" echo "==> Fetching release metadata" curl -fsSL "$(release_api_url)" -o "$release_json" local tag asset_name asset_url checksum_name checksum_url mapfile -t meta < <(select_assets "$release_json" "$os" "$arch") if [[ "${#meta[@]}" -lt 5 ]]; then echo "error: failed to resolve release assets for ${os}/${arch}" >&2 exit 1 fi tag="${meta[0]}" asset_name="${meta[1]}" asset_url="${meta[2]}" checksum_name="${meta[3]}" checksum_url="${meta[4]}" local asset_file="${tmpdir}/${asset_name}" echo "==> Downloading ${asset_name} (${tag})" curl -fsSL "$asset_url" -o "$asset_file" local checksums_file="" if [[ -n "$checksum_url" ]]; then checksums_file="${tm ...[truncated 2943 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (152)

Tainted flow: 'req' from os.environ.get (line 183, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/xai_collections.py (reported line 110)May include surrounding context.

python
req = urllib.request.Request(url, data=data, method=method.upper(), headers=headers)
    try:
        with urllib.request.urlopen(req, timeout=timeout_s) as resp:
            txt = resp.read().decode("utf-8", errors="replace")
            return (json.loads(txt) if txt else {}), plan
    except urllib.error.HTTPError as e:

Tainted flow: 'req' from os.environ.get (line 183, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/xai_collections.py (reported line 185)May include surrounding context.

python
req = urllib.request.Request(url, data=data, method=method.upper(), headers=headers)
    try:
        with urllib.request.urlopen(req, timeout=timeout_s) as resp:
            txt = resp.read().decode("utf-8", errors="replace")
            return (json.loads(txt) if txt else {}), plan
    except urllib.error.HTTPError as e:

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The '| bash' construct is a classic command-chaining pattern that turns a content fetch into immediate shell execution. In practice, it removes any inspection barrier and makes malicious modification of the fetched content immediately exploitable as arbitrary command execution.

Content

Scanner excerpt · README.md (reported line 34)May include surrounding context.

Install

bash
curl -fsSL https://raw.githubusercontent.com/0xNyk/xint-rs/main/install.sh | bash

Optional pinned version:

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

This command repeats the same unsafe fetch-and-execute chain, so the exploitation path remains identical: any compromise of the fetched script results in arbitrary shell execution. In agent contexts, such one-liners are particularly dangerous because they are easy to copy, automate, or invoke without review.

Content

Scanner excerpt · README.md (reported line 41)May include surrounding context.

bash
XINT_RS_INSTALL_VERSION=<version-tag> \
curl -fsSL https://raw.githubusercontent.com/0xNyk/xint-rs/main/install.sh | bash

Homebrew (lightweight prebuilt binary on Apple Silicon):

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 121)May include surrounding context.

Setup

bash
cp .env.example .env
# Add X_BEARER_TOKEN=your_token

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README claims 'No telemetry, no phone-home' while earlier sections document optional hosted cloud/control-plane connectivity and remote package API communication. This is a security-significant contradiction because users and agents may rely on the claim to assume no outbound data transfer, when the tool can in fact send data to remote endpoints if configured.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description is for the functionality of the xint CLI tool, but the provided code chunk does not implement any of those user-facing capabilities. Instead, it is an installation helper script that downloads and installs the prebuilt xint binary from GitHub. This is a materially different primary purpose for the supplied code chunk. While an installer can be a supporting component of the overall project, the task is to compare the declared skill description against what this specific code actually does, and they do not match.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is about end-user X/Twitter research and analysis functionality. The supplied code chunk does not implement any X/Twitter search, analysis, monitoring, reporting, or engagement features. Instead, it is a release helper that delegates to another shell script. This is a materially different primary purpose from the declared skill behavior, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This code chunk does not implement the declared X/Twitter intelligence behavior. Instead, it interacts with xAI endpoints (api.x.ai and management-api.x.ai) to list/create/ensure collections, upload files, attach documents to collections, search documents, and bulk sync a local directory into a collection while writing a local markdown report. The primary purpose is knowledge-base/collections management for xAI, not X/Twitter research or engagement. That is a material description-behavior mismatch, with undeclared capabilities around local file ingestion and collection management, and missing the core declared social/X features.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The description presents a broad Rust CLI for searching, analyzing, monitoring, and engaging on X/Twitter, with many features beyond search. The supplied code chunk is much narrower: it only submits x_search requests to xAI's API, extracts results and optional summary text, writes markdown/JSON artifacts, and optionally emits memory candidates into workspace storage. That memory-store integration is an undeclared capability, and the described engagement/social-management features are absent in this code. While parts of the description do overlap with the code (search, report-like output, some analysis text from Grok), the code's actual behavior is materially narrower and includes storage behavior not represented in the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description correctly covers several major capabilities present in the CLI: search, watch, report, follower diff, trends, Grok analysis, bookmarks, likes, following, x-search, collections, and exports. However, the code exposes many additional substantive capabilities not disclosed in the description. Most notably, it includes moderation actions (blocks/mutes), follow/unfollow, list management, official filtered stream and stream rule management, media download, article retrieval/analysis, OAuth auth flows, MCP server mode, and a suite of account analytics/audit tools. These are not merely internal details; they are user-facing commands with distinct purposes and resources. There is also tension with the explicit non-goal 'Not for enterprise features' because the code includes stream/rule management and an MCP server, both beyond the narrowly described intelligence CLI scope. The description is therefore materially incomplete and somewhat misleading about what the tool can do.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description is broadly about an X intelligence CLI, and the manifest code is related because it advertises capabilities for such a tool. However, there are material mismatches. Most importantly, the manifest explicitly declares a tweet capability under X API v2, which contradicts the non-goal 'Not for posting tweets.' The manifest also includes enterprise_controls policy metadata, conflicting with 'not for enterprise features.' Additionally, this specific code chunk does not execute the described user-facing operations; it only reports metadata about capabilities, pricing, and policies. While that can be a supporting implementation detail, the explicit inclusion of a posting capability makes the description inaccurate.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code chunk is unrelated to X/Twitter intelligence functionality described in the skill declaration. It dispatches subcommands for cost summaries and budget management using a local costs_path, including setting/checking a daily budget and resetting today's tracked costs. These are materially different capabilities from searching/analyzing/engaging on X/Twitter. This is not just an internal support detail for the declared purpose; it exposes a separate user-facing command with unrelated behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The supplied code does not implement the description’s primary advertised intelligence capabilities such as search, monitoring/watch, sentiment/analysis with Grok, reports, follower diffing, or trends. Instead, this chunk is focused on engagement/account actions: likes, bookmarks, and follow/unfollow operations, plus listing likes and following. Some of these capabilities are briefly mentioned in the description under 'Also supports' (bookmarks, likes, following), so they are not wholly undeclared. However, there is still a material description-behavior mismatch for this specific code chunk because the declared purpose emphasizes research/intelligence use cases and even says 'Not for posting tweets' while this code actively performs write actions on the user’s account (like, bookmark, follow, unfollow). Those are engagement capabilities rather than search/analysis behavior, making the code’s actual primary purpose different from the declared one for this chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code chunk is focused on managing Twitter/X Lists and list membership, which is not represented in the declared description. The description emphasizes research/search/monitoring/analysis/reporting/trends and mentions bookmarks, likes, following, collections, and export, but does not mention list CRUD or membership management. This is a substantive undeclared capability rather than an internal implementation detail. It also uses OAuth-authenticated write operations despite the declared permissions being empty. While it is still within the broader X/Twitter domain, the specific behavior of creating, modifying, and deleting lists and changing list membership is materially absent from the declared purpose, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code chunk’s primary function is downloading media attachments from a tweet and writing them to disk. That is a substantive capability not represented in the declared description, which emphasizes search, monitoring, analysis, reports, trends, follower diffs, bookmarks/likes/following, and exports. While interacting with X/Twitter is consistent at a high level, media retrieval/downloading is a separate user-facing feature and not a mere implementation detail of search or analysis. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The declared description centers on an X/Twitter intelligence CLI for search, monitoring, analysis, reports, trends, and some account interaction features such as bookmarks, likes, and following, while explicitly stating it is not for posting tweets. The code chunk only exposes module names, so behavior cannot be proven in detail, but several modules suggest capabilities beyond the declared scope. In particular, tweet, thread, and reposts imply content creation or active engagement features that may conflict with the stated non-goal of 'Not for posting tweets.' Additional modules like moderation, content_audit, media, article, and tui indicate notable capabilities omitted from the description. While many modules align with the stated purpose (search, watch, analyze, report, diff, trends, bookmarks, collections, x_search), the undeclared and potentially contradictory modules make the description appear incomplete and possibly misleading.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code is not about search, research, monitoring, sentiment analysis, reports, trends, follower diffs, bookmarks, likes, or collections. Instead, it provides active moderation/account-control features: list/add/remove blocks and mutes using authenticated OAuth requests to user moderation endpoints. That is a materially different capability from the declared purpose and is not mentioned in the description; in fact, the description focuses on intelligence/research use cases and says it is not for certain engagement actions. While blocking/muting is not the same as posting, it is still an undeclared account-management feature unrelated to the described primary purpose. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description is broad and specific about X/Twitter intelligence capabilities: search, watch/monitoring, sentiment/analysis, reports, follower diffs, trends, bookmarks/likes/following, and exports. The supplied code chunk, however, is a minimal wrapper for a tui command that simply delegates to crate::tui::run(policy). Based on this chunk alone, the observable behavior is launching a text user interface, which is not explicitly represented in the declared description and does not substantiate the listed capabilities. Because the actual code shown has a materially narrower and different immediate purpose than the declared feature set, this is a mismatch for this chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The core behavior generally matches part of the description: it performs search queries, collects results/summaries/citations, and exports JSON/Markdown reports. However, this code also performs an additional capability not stated in the declared purpose: it reads from a local workspace memory system and appends extracted result snippets as 'memory candidates' to JSONL files. That is persistent knowledge-ingestion behavior, not merely search/report export. The description mentions export formats but not memory-store interaction or fact extraction into a separate memory pipeline. Also, while the skill is framed as X/Twitter intelligence, the code exposes allow/exclude domain filtering and uses an xAI search call that may not be strictly limited to X posts from the code shown, making the implementation somewhat broader than the declared X/Twitter-only purpose. Therefore this chunk is a partial but meaningful description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

There is a clear description-behavior mismatch. Most of the code aligns with an X/Twitter CLI for search, monitoring, analysis, trends, bookmarks, likes, following, auth, collections, and x-search. However, the description explicitly states a non-goal: 'Not for posting tweets.' The code includes Commands::Tweet(args) => commands::tweet::run(...), which strongly indicates a tweet-posting or tweet-action capability. That is a material contradiction, not just an omitted minor feature. The code also exposes several additional capabilities not mentioned in the declared purpose, such as blocks/mutes moderation, stream/stream-rules management, analytics/top/growth/timing/content-audit, and other account/content utilities. Those extra features alone might be acceptable as under-described extensions, but the explicit contradiction around tweet posting makes this a definite mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

There is substantial overlap with the declared X/Twitter intelligence functionality: the code exposes search, profiles, threads, tweets, trends, watch, diff, Grok analysis, sentiment, collections search/list, cache clearing, and cost tracking. However, this chunk’s primary implemented role is specifically an MCP server wrapper for AI agents, communicating over JSON-RPC via stdio, which is not reflected in the description. More importantly, it adds a distinct, undeclared capability set around 'packages'—remote package creation, querying with citation enforcement, refreshing, searching, and publishing to shared catalogs through a separate package API using environment-configured endpoints and auth headers. Those package/memory/cloud features are materially beyond the declared scope of a fast X intelligence CLI. Additionally, some described functions are only stubbed or reduced in this MCP layer (article route only acknowledges, bookmarks returns an info note, report returns source data without AI narrative), reinforcing that the behavior is not accurately represented by the description alone.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The code chunk is a dispatcher, so by itself it does not execute the underlying actions; however, it exposes the set of supported tool routes. Several routed capabilities are not represented in the description, especially package creation/publishing/query/status operations, cache clearing, and costs. More importantly, the presence of an xint_tweet route conflicts with the declared non-goal 'Not for posting tweets' unless 'tweet' is strictly read-only retrieval, which the description does not clarify. The code also includes profile, thread, and article routes that are not mentioned. While many declared capabilities are aligned (search, trends, watch, diff, report, sentiment, bookmarks, collections), the available routed tool surface materially exceeds the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code chunk itself is a policy/authorization module rather than implementation of X actions, so its primary behavior is a supporting detail and broadly consistent with a CLI that exposes many X-related commands. However, the command surface enumerated here materially contradicts the declared description in one important way: it includes a 'Tweet' command, while the description explicitly says the skill is not for posting tweets. Additionally, the presence of moderation commands like blocks and mutes suggests extra capabilities not disclosed in the description. The strongest mismatch is the explicit tweet/posting capability versus the stated non-goal.

Content

No source excerpt is available for this finding.

Exfiltration Commands

High
Category
Prompt Injection
Confidence
96% confidence
Finding

A feature explicitly designed to send monitored data to external URLs is a high-risk exfiltration mechanism. In this skill context, the danger is elevated because outputs may include sensitive queries, account-linked observations, exports, or other collected intelligence that users may not intend to share onward.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
- Review exported data before sharing - may contain sensitive search queries

### Webhooks
- The `watch` command supports `--webhook` to send data to external URLs
- Only use webhooks you control (your own servers, Slack/Discord you own)
- Don't pass sensitive URLs as webhook targets

Static analysis

No suspicious patterns detected.