Back to skill

Security audit

Openclaw Twitter Post Engage

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly transparent about Twitter/X relay use, but needs review because media uploads can send arbitrary readable local files and the relay API key is redundantly placed in request bodies.

Install only if you trust the AISA relay and are comfortable granting it OAuth-backed Twitter/X posting and engagement authority. Use explicit, reviewed media paths from your workspace, avoid sensitive local files, review OAuth scopes, and prefer a restricted or rotating AISA_API_KEY because the current clients send that key in request bodies as well as headers.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/twitter_oauth_client.py:384
Finding

Relay API Key Is Duplicated in Authorization Headers and Request Bodies

Content
View full analysis
Dict[str, str]: headers = { "Authorization": f"Bearer {aisa_api_key}", "User-Agent": DEFAULT_CHROME_USER_AGENT, } if extra_headers: headers.update(extra_headers) return headers ``` The posting client then duplicates the same credential in the request body: ```python def post_single_tweet( config: Dict[str, Any], *, content: Optional[str] = None, media_ids: Optional[list[str]] = None, media_files: Optional[list[Dict[str, Any]]] = None, parent_tweet_id: Optional[str] = None, post_type: Optional[str] = None, ) -> Dict[str, Any]: payload: Dict[str, Any] = { "aisa_api_key": config["aisa_api_key"], } if content: payload["content"] = content if post_type: payload["type"] = post_type if media_ids: payload["media_ids"] = media_ids if parent_tweet_id: parent_key = "in_reply_to_tweet_id" if post_type == "reply" else "quote_tweet_id" payload[parent_key] = parent_tweet_id endpoint = f"{config['base_url']}/post_twitter" if media_files: return send_multipart_request( endpoint, payload, media_files, timeout=config["timeout"], ...[truncated 3004 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/twitter_oauth_client.py:418
Finding

Media Upload Accepts Unrestricted Local Paths Without Workspace or Size Enforcement

Content
View full analysis
list[Dict[str, Any]]: if not paths: return [] media_files: list[Dict[str, Any]] = [] media_kinds: set[str] = set() seen_paths: set[str] = set() for raw_path in paths: resolved_path = os.path.abspath(os.path.expanduser(raw_path)) normalized_path = os.path.normcase(resolved_path) if normalized_path in seen_paths: continue seen_paths.add(normalized_path) if not os.path.exists(resolved_path): raise RelayConfigError(f"Media file does not exist: {raw_path}") if not os.path.isfile(resolved_path): raise RelayConfigError(f"Media path is not a file: {raw_path}") mime_type = mimetypes.guess_type(resolved_path)[0] or "application/octet-stream" media_kind = mime_type.split("/", 1)[0] if media_kind not in {"image", "video"}: raise RelayConfigError( f"Unsupported media type for {raw_path}: {mime_type}. Only image and video files are supported." ) media_kinds.add(media_kind) with open(resolved_path, "rb") as file_handle: content = file_handle.read() media_files.append( { "field_name": "media_files", "filename": os.path.basename(resolved_path), "content_type": mime_type, "content": content, } ) ``` ### Technical Analysis The documentation describes `--media-file` as accepting attachment paths from a local workspace. The implementation does not enforce that boundary. It expands home-directory notation, converts input to an absolute path, follows filesystem links through ordinary file operations, and accepts ...[truncated 2853 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding indicates the documented feature set is substantially broader than the observed code, with only /auth_twitter and /post_twitter implemented while search, follow, like, and broader read APIs are claimed. Such discrepancy is a security issue because policy engines, users, and auditors may make trust decisions based on inaccurate declarations, especially for write-capable social-media operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This finding indicates the documented feature set is substantially broader than the observed code, with only /auth_twitter and /post_twitter implemented while search, follow, like, and broader read APIs are claimed. Such discrepancy is a security issue because policy engines, users, and auditors may make trust decisions based on inaccurate declarations, especially for write-capable social-media operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This finding indicates the documented feature set is substantially broader than the observed code, with only /auth_twitter and /post_twitter implemented while search, follow, like, and broader read APIs are claimed. Such discrepancy is a security issue because policy engines, users, and auditors may make trust decisions based on inaccurate declarations, especially for write-capable social-media operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README advertises posting and engagement capabilities but does not prominently warn that these operations can change a user's account state and may have reputational or operational consequences. In this skill context, the absence of a clear warning is more dangerous because the skill is specifically designed to interact with X/Twitter via OAuth-gated actions, making unintended likes, follows, or posts plausibly actionable.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill declares access to environment variables and clearly states that it makes network calls to an external relay, but it does not define any explicit tool scope such as allowed tools or permissions. That weakens sandboxing and reviewability because an agent may invoke the skill without a precise declaration of the sensitive capabilities it needs.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
81% confidence
Finding

The skill explicitly sends data and authorization-related traffic to an external service at api.aisa.one. External transmission is not inherently malicious here, but it is security-relevant because prompts, account metadata, OAuth artifacts, or posting content may leave the local environment and be exposed to a third-party relay.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

export AISA_API_KEY="your-key"

text

All network calls go to `https://api.aisa.one/apis/v1/...`.

## Capabilities

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/engage_twitter.md (reported line 27)May include surrounding context.

md
When the user asks to like, unlike, follow, or unfollow on X/Twitter:

1. Do not ask the user to manually paste tweet links or IDs.
2. If the user first asked to query tweets, keep the returned `tweets[]` structure in OpenClaw context.
3. Map ordinal follow-up requests to remembered tweet or author context.
4. If multiple user candidates match a natural-language name, stop and ask the user to confirm the account.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/post_twitter.md (reported line 88)May include surrounding context.

md
When the user asks to like, unlike, follow, or unfollow on X/Twitter:

1. Do not ask the user to manually paste tweet links or IDs.
2. If the user first asked to query tweets, keep the returned `tweets[]` structure in OpenClaw context.
3. Map ordinal follow-up requests to remembered tweet or author context.
4. If multiple user candidates match a natural-language name, stop and ask the user to confirm the account.

External Transmission

Medium
Category
Data Exfiltration
Confidence
79% confidence
Finding

The skill is designed around transmitting data and a bearer credential to an external API endpoint, which creates a real external data exposure boundary. In this skill context, external transmission is expected, but it is still security-relevant because prompts, search terms, usernames, and tweet identifiers may contain sensitive operational context, and compromise or misuse of the relay could expose that data.

Content

Scanner excerpt · scripts/twitter_client.py (reported line 35)May include surrounding context.

python
class TwitterClient:
    """OpenClaw Twitter - Twitter/X API Client."""

    BASE_URL = "https://api.aisa.one/apis/v1"

    def __init__(self, api_key: Optional[str] = None):
        """Initialize the client with an API key."""

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The client forwards user-provided queries, usernames, tweet IDs, and similar identifiers to a third-party relay service without any in-band disclosure, confirmation, or minimization. In an agent skill context, this can leak sensitive research targets, private investigative interests, or regulated identifiers to an external provider unexpectedly.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/twitter_oauth_client.py (reported line 29)May include surrounding context.

python
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1/twitter"
DEFAULT_CHROME_USER_AGENT = (
    "Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
    "AppleWebKit/537.36 (KHTML, like Gecko) "

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README's 'Use when' guidance is broad enough to route many generic social-media requests into a skill that can perform account-affecting actions such as posting, liking, and following. In an agentic environment, ambiguous invocation criteria can increase the chance of the skill being selected without clear confirmation that the user intended an action-capable workflow rather than read-only research.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The module docstring and CLI description present this script as a 'Twitter/X read APIs' client focused on user, tweet, and trend reads. However, the implemented methods also include social-graph and community/list enumeration such as followers, followings, verified followers, follow-relationship checks, list followers/members, and community membership/moderator discovery, which goes materially beyond the narrower documented framing.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The top-level docstring and argparse description frame the tool as a generic read API client, with examples centered on user info and tweet search. The actual command set includes follow-relationship checking, follower/following enumeration, verified follower lookup, list follower/member retrieval, and community moderator/member enumeration, so the documentation understates the operational intent of the tool.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.