Back to skill

Security audit

X Publisher

Security checks for vulnerabilities and agentic risk

Overview

This skill is an X/Twitter account automation tool that mostly matches its purpose, but it under-discloses delete, like, and timeline access and gives no confirmation guard for deleting live account content.

Install only if you are comfortable giving this skill OAuth credentials for a real X/Twitter account. Treat it as able to post, reply, quote, like, delete tweets, and read recent account tweets; require explicit user approval before any delete or public engagement action, and do not rely on the documented scheduling commands unless the implementation is updated.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest says the skill posts tweets, threads, replies, and quote-tweets, but the documented commands also support liking, deleting, and reading timeline data. This mismatch can mislead reviewers and users about the true power of the skill, increasing the chance of unauthorized destructive or privacy-impacting actions being invoked.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
- `X_API_KEY` — X API key (OAuth 1.0a consumer key)
- `X_API_SECRET` — X API secret
- `X_ACCESS_TOKEN` — Access token
- `X_ACCESS_SECRET` — Access token secret

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
- `X_API_KEY` — X API key (OAuth 1.0a consumer key)
- `X_API_SECRET` — X API secret
- `X_ACCESS_TOKEN` — Access token
- `X_ACCESS_SECRET` — Access token secret

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill requires environment-based credentials and instructs execution of a local script, but it does not declare any explicit tool scope such as permissions or allowed-tools. That omission weakens reviewability and policy enforcement because consumers cannot easily see that the skill depends on sensitive env-backed capabilities before use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documented command set materially exceeds the stated description, so the manifest understates what the skill can do. Understated capabilities reduce transparency and make it harder for operators to apply informed approval, especially where account-modifying and content-deleting operations are present.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents a delete command for tweets without any warning, dry-run option, or confirmation guidance. In an agent setting, destructive actions without friction increase the risk of accidental or unauthorized content removal from a live account.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill’s declared purpose is posting to X, but it also supports liking tweets, deleting tweets, and reading the user timeline. Those extra capabilities expand the available attack surface and allow state-changing actions beyond the minimum needed for posting, which is dangerous in an agent context because a prompt-injected or misused agent could perform unintended account actions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · x-api.js (reported line 86)May include surrounding context.

js
if (!queryParams) queryParams = {};
  return new Promise(function(resolve, reject) {
    const credentials = getCredentials();
    const urlObj = new URL('https://api.twitter.com/2' + path);
    Object.keys(queryParams).forEach(function(k) {
      urlObj.searchParams.append(k, queryParams[k]);
    });

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · x-api.js (reported line 177)May include surrounding context.

js
if (!queryParams) queryParams = {};
  return new Promise(function(resolve, reject) {
    const credentials = getCredentials();
    const urlObj = new URL('https://api.twitter.com/2' + path);
    Object.keys(queryParams).forEach(function(k) {
      urlObj.searchParams.append(k, queryParams[k]);
    });

Static analysis

No suspicious patterns detected.