Back to skill

Security audit

xurl

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent X API helper, but it enables public/account-changing actions and arbitrary authenticated API calls without clear confirmation guardrails.

Install only if you intend to let the agent use an authenticated X account. Treat posts, deletes, DMs, follow/block/mute actions, media uploads, auth app removal, and any raw non-GET API request as confirmation-required operations, and review the exact endpoint, method, and payload before execution. Prefer read-only commands unless you clearly requested an account-changing action.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:9
Finding

Unpinned Third-Party CLI Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 9–24
Vulnerability Type: Unpinned third-party dependencies from mutable package channels
Risk Level: Medium

Vulnerable Code

json
"install":
  [
    {
      "id": "brew",
      "kind": "brew",
      "formula": "xdevplatform/tap/xurl",
      "bins": ["xurl"],
      "label": "Install xurl (brew)",
    },
    {
      "id": "npm",
      "kind": "node",
      "package": "@xdevplatform/xurl",
      "bins": ["xurl"],
      "label": "Install xurl (npm)",
    },
  ],

Technical Analysis

The skill defines Homebrew and npm installation sources for the xurl executable without specifying an immutable version, source revision, checksum, or package integrity value. Consequently, the installed artifact is resolved from mutable package channels at installation time and may differ from the version represented during this audit.

This creates a supply-chain risk: compromise of the package publisher, registry account, Homebrew tap, or release pipeline could cause future installations to retrieve attacker-controlled code. The finding does not establish that the current xurl packages are malicious; it identifies the absence of controls that ensure users receive a previously reviewed artifact.

Attack Path

  1. An attacker compromises the npm publisher account, Homebrew tap, upstream release process, or another relevant distribution component.
  2. The attacker publishes a malicious release under the expected @xdevplatform/xurl package or xdevplatform/tap/xurl formula.
  3. A user or agent installs the dependency through the skill metadata without an immutable version or integrity constraint.
  4. The package manager resolves and installs the attacker-controlled release.
  5. Malicious installation hooks or executable code run with the privileges of the installing user.
  6. Because xurl is intended to access an authenticated X acc ...[truncated 670 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the npm dependency to a specific reviewed version instead of allowing resolution to an unspecified current release.
  • Pin the Homebrew installation source to an immutable, reviewed formula revision or otherwise document and enforce the expected release version.
  • Validate downloaded artifacts with trusted checksums, signatures, or package integrity metadata where supported.
  • Configure automated dependency monitoring so version changes require explicit review before adoption.
  • Verify package ownership, canonical source repositories, and release provenance.
  • Prefer reproducible installation procedures and retain an allowlist of approved artifact hashes.
  • Run installation and subsequent CLI use with the minimum necessary operating-system and X API privileges.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
## Secret safety

- Never read, print, summarize, upload, or inspect `~/.xurl`.
- Never ask user to paste tokens/secrets into chat.
- Do not run auth commands with inline secrets.
- Do not use `--verbose` in agent sessions; it can expose auth headers.
- Check auth with `xurl auth status`.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documents account-affecting and potentially irreversible actions such as delete, follow/unfollow, block, mute, DM, and repost without an explicit warning to require clear user confirmation before execution. In an agent context, this increases the chance that a model may carry out unintended authenticated actions on the user's X account, causing reputational, privacy, or account-state harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The raw API section encourages arbitrary authenticated v2 requests, including POST operations, without warning that these calls can create, modify, or delete remote account data. In an agent setting, generic raw-call capability broadens the attack surface and makes it easier for prompt confusion or misuse to trigger unintended state-changing operations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.