T09 · Insecure Skill Coding Practices
- Location
scripts/twitter_oauth_client.py:342- Finding
AISA API Key Exposed in OAuth Client Standard Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its Twitter/X research and posting purpose, but its OAuth/posting client exposes the configured AISA API key in normal command output.
Review carefully before installing. The relay-based Twitter/X access and media uploads are expected for this skill, but do not use it with a valuable AISA_API_KEY until the client stops printing that key in command output. Treat any existing logs or transcripts from authorize/post runs as potentially containing the secret and rotate the key if exposed.
scripts/twitter_oauth_client.py:342AISA API Key Exposed in OAuth Client Standard Output
The skill is marketed as supporting Twitter research and monitoring, but the underlying capability set reportedly only exposes authorize/post/status style endpoints and lacks the advertised search and retrieval functions. This kind of description-behavior mismatch is dangerous because it can conceal the skill's true operational focus, causing users or orchestrators to invoke a posting-capable integration under the assumption that it is read-oriented and low risk.
The skill is marketed as supporting Twitter research and monitoring, but the underlying capability set reportedly only exposes authorize/post/status style endpoints and lacks the advertised search and retrieval functions. This kind of description-behavior mismatch is dangerous because it can conceal the skill's true operational focus, causing users or orchestrators to invoke a posting-capable integration under the assumption that it is read-oriented and low risk.
The status and posting flows include the full AISA API key in JSON output, which can leak secrets to terminal history, logs, wrappers, CI systems, or calling agents. Because this skill is intended for Twitter research/posting rather than credential display, exposing the bearer token is unnecessary and materially increases the chance of account or relay abuse if the output is captured.
The authorize command prints the raw AISA API key together with the authorization URL, directly disclosing a bearer credential during a routine user flow. This is dangerous because authorization responses are likely to be copied, logged, or surfaced by higher-level tooling, allowing anyone with access to the output to reuse the key against the AIsa API.
The skill declares access to environment secrets and makes external network calls, but it does not define any explicit tool scope or permission boundaries. In an agent ecosystem, this weakens least-privilege controls and can allow broader-than-expected access to secrets and outbound communication, increasing the blast radius if the skill is misused or compromised.
The skill explicitly instructs agents to pass local workspace file paths and tweet content to a relay backend at an external domain, but it does not require a clear user-facing disclosure that those local files and post contents will be transmitted off-host. In an agent setting, this can cause users to unknowingly send sensitive media or text to a third-party service, especially when attachments originate from the local workspace and may contain private data.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Guardrails
- Do not ask the user for their Twitter password.
- Do not use cookie-based login or proxy-based login unless the user explicitly asks for legacy behavior.
- Do not default to `--open-browser`; return the authorization link unless the user explicitly wants local browser launch.
- Do not invent remote URLs for attachments; always use the provided local workspace file path with `--media-file`.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1"
DEFAULT_CHROME_USER_AGENT = (
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
"AppleWebKit/537.36 (KHTML, like Gecko) "
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1"
DEFAULT_CHROME_USER_AGENT = (
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
"AppleWebKit/537.36 (KHTML, like Gecko) "
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1"
DEFAULT_CHROME_USER_AGENT = (
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
"AppleWebKit/537.36 (KHTML, like Gecko) "
The post command reads local media files and sends post text, media IDs, and file contents to the remote AIsa service via HTTP requests, but this command path provides no explicit user-facing disclosure before transmission. Although network posting is part of the tool's purpose, the code lacks any warning that local file contents and tweet content are being uploaded to an external service.
The authorize flow constructs a payload containing the AISA API key and transmits it to the /twitter/auth_twitter endpoint, but the command does not print or document that credential-bearing data is being sent. There is no confirmation prompt or warning in this file beyond internal code behavior.
No suspicious patterns detected.