Back to skill

Security audit

x-twitter-automation

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real X/Twitter automation skill, but it can read/send DMs and publish, delete, follow, like, and repost from a connected account with limited built-in approval guidance.

Install only if you are comfortable giving AgentPMT-controlled workflows access to operate your connected X/Twitter account, including private DMs and public account actions. Use narrow account scopes where possible, require human approval for posts, replies, DMs, follows, reposts, and deletes, and avoid using engagement actions solely to unlock unsolicited replies.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (19)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises high-impact capabilities such as posting, engaging, following, and sending DMs without a dedicated warning section explaining abuse, privacy, consent, or destructive-action risks. In an agent setting, that omission can cause unsafe autonomous use, especially where actions affect public accounts or private communications.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow explicitly tells the agent to first like or repost posts so it becomes eligible to reply, which operationalizes a staged bypass of the platform's intended reply restriction. This is dangerous because it converts a guardrail into a procedural hurdle and enables automated unsolicited engagement and outreach at scale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

delete_post is documented as a normal action without clearly stating that deletion may be irreversible or operationally harmful if triggered by mistake or prompt injection. For an autonomous agent controlling a social account, destructive operations need explicit caution and confirmation guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill exposes lookup_dms and send_dm capabilities without a clear privacy and consent warning, despite handling private communications and potentially sensitive personal data. In an agent context, this increases the chance of unauthorized reading, disclosure, or messaging of private conversations.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The notes section reinforces the same pattern by instructing the agent to engage with a post first in order to reply, creating a progressive permission-escalation workflow. In this context, the skill is not merely documenting a restriction; it is teaching the agent how to circumvent it using intermediate actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 402)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/x-twitter-automation
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 403)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/x-twitter-automation
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes composing, publishing, searching, engaging, and DMing on X/Twitter, but this schema also exposes extensive X List management operations: creating, deleting, updating Lists, following/unfollowing Lists, pinning/unpinning Lists, inspecting List contents, and changing List membership. Those administrative List capabilities go beyond the concrete behaviors claimed in the manifest description and are not mentioned there.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Destructive actions such as deleting posts, DMs, or Lists are documented without explicit warnings about irreversibility or confirmation expectations. In an agentic context, this increases the risk of accidental or prompt-induced destructive operations that can cause permanent content loss and account impact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill exposes DM read and send capabilities without privacy warnings, despite granting access to potentially sensitive private communications and enabling outbound messaging. In an agent workflow, this can lead to unintended collection, disclosure, or abuse of private messages if users are not clearly warned about the sensitivity of these actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest frames the skill around post/reply/search/engagement/DM automation, but the schema also includes separate media lifecycle operations such as uploading media from file IDs or public URLs, setting alt text and video download permissions, and attaching/removing subtitle tracks. These are meaningful capabilities not reflected in the manifest's stated scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

Beyond publishing and recent post search, the schema supports broad read operations including user lookup/search, follower/following inspection, liked-post inspection, community discovery, news lookup, and trends lookup. While some monitoring is mentioned in the manifest, these discovery and account-inspection capabilities are broader than the specific description provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.