T09 · Insecure Skill Coding Practices
- Location
scripts/twitter_oauth_client.py:337- Finding
API Key Exposed in Command Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a disclosed Twitter/X relay, but it needs review because its posting/OAuth client prints the AIsa API key and can upload caller-selected local media files.
Review carefully before installing. Only use it with an AIsa key you are willing to expose to local command logs, avoid attaching sensitive local files, and treat posting as a public account action mediated by the AIsa relay. Rotate the key if it has already appeared in agent or CI output.
scripts/twitter_oauth_client.py:337API Key Exposed in Command Output
scripts/twitter_oauth_client.py:415Unrestricted Local File Selection for Network Upload
If the underlying implementation lacks the advertised research, monitoring, search, and watchlist features while still enabling direct posting or media upload, users may invoke the skill under false assumptions and unintentionally authorize content publication to a third party. In a social-media skill, hidden emphasis on posting is more dangerous because it can lead to reputation harm, account misuse, or accidental data sharing despite a seemingly research-oriented description.
If the underlying implementation lacks the advertised research, monitoring, search, and watchlist features while still enabling direct posting or media upload, users may invoke the skill under false assumptions and unintentionally authorize content publication to a third party. In a social-media skill, hidden emphasis on posting is more dangerous because it can lead to reputation harm, account misuse, or accidental data sharing despite a seemingly research-oriented description.
The skill declares required environment access and relies on outbound network communication, but it does not explicitly constrain tool scope with permissions or allowed-tools metadata. That omission can cause the host agent to grant broader execution latitude than users expect, increasing the risk of unintended secret access or network actions when invoking the skill.
The skill explicitly sends user requests, OAuth-related data, and potentially attached local media files to a fixed third-party endpoint. External transmission is expected for this kind of integration, but it is still security-relevant because API keys, uploaded content, and account-linked actions leave the local environment and depend on the remote service's trustworthiness and data handling.
- `AISA_API_KEY` is required for AIsa-backed API access.
- Use repo-relative `scripts/` paths from the shipped package.
- Twitter/X reads, OAuth requests, and user-approved media uploads use the fixed AIsa API endpoint `https://api.aisa.one/apis/v1/twitter`.
- Provide only `AISA_API_KEY`; do not use passwords, cookies, or browser credential export.
## Example Requests
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Guardrails
- Do not ask the user for their Twitter password.
- Do not use cookie-based login or proxy-based login unless the user explicitly asks for legacy behavior.
- Do not default to `--open-browser`; return the authorization link unless the user explicitly wants local browser launch.
- Do not invent remote URLs for attachments; always use the provided local workspace file path with `--media-file`.
The inline documentation repeatedly frames the script as read-only, including usage comments for 'read' and the CLI description. In contrast, _request contains a POST branch that encodes JSON request bodies, which contradicts the stated read-only intent rather than merely omitting detail.
The top-level docstring presents this script as a read-only Twitter/X client and specifically describes read operations using GET. However, the shared _request method includes logic to serialize request bodies for POST requests, indicating write-capable plumbing exists despite the read-only positioning. That is a semantic mismatch between the documented scope and implemented behavior.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1"
DEFAULT_CHROME_USER_AGENT = (
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
"AppleWebKit/537.36 (KHTML, like Gecko) "
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1"
DEFAULT_CHROME_USER_AGENT = (
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
"AppleWebKit/537.36 (KHTML, like Gecko) "
The post flow transmits tweet text, media, and the AISA API key to a third-party remote service, but the CLI provides no explicit disclosure or confirmation at the point of transmission. In a local automation skill, this can cause users to unknowingly exfiltrate sensitive draft content or local files to an external API, especially when invoked by another agent or workflow.
The authorization command sends a credential-bearing request containing the AISA API key to a remote endpoint to obtain an authorization URL without prominent disclosure to the user. In the context of an OAuth/posting skill, that increases the risk of users authorizing an external relay service without understanding that account-linking metadata and secrets are being shared off-host.
The module docstring lists an authorize command with an --open-browser option, and the CLI parser also exposes that flag, implying local browser launch support. However, when the flag is used, the code only prints that browser auto-open is disabled and never calls webbrowser.open, which contradicts the documented command behavior.
No suspicious patterns detected.