Back to skill

Security audit

AIsa Twitter Command Center

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Twitter/X research and posting purpose, but its OAuth/posting client exposes the configured AISA API key in normal command output.

Review carefully before installing. The relay-based Twitter/X access and media uploads are expected for this skill, but do not use it with a valuable AISA_API_KEY until the client stops printing that key in command output. Treat any existing logs or transcripts from authorize/post runs as potentially containing the secret and rotate the key if exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/twitter_oauth_client.py:342
Finding

AISA API Key Exposed in OAuth Client Standard Output

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is marketed as supporting Twitter research and monitoring, but the underlying capability set reportedly only exposes authorize/post/status style endpoints and lacks the advertised search and retrieval functions. This kind of description-behavior mismatch is dangerous because it can conceal the skill's true operational focus, causing users or orchestrators to invoke a posting-capable integration under the assumption that it is read-oriented and low risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is marketed as supporting Twitter research and monitoring, but the underlying capability set reportedly only exposes authorize/post/status style endpoints and lacks the advertised search and retrieval functions. This kind of description-behavior mismatch is dangerous because it can conceal the skill's true operational focus, causing users or orchestrators to invoke a posting-capable integration under the assumption that it is read-oriented and low risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The status and posting flows include the full AISA API key in JSON output, which can leak secrets to terminal history, logs, wrappers, CI systems, or calling agents. Because this skill is intended for Twitter research/posting rather than credential display, exposing the bearer token is unnecessary and materially increases the chance of account or relay abuse if the output is captured.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The authorize command prints the raw AISA API key together with the authorization URL, directly disclosing a bearer credential during a routine user flow. This is dangerous because authorization responses are likely to be copied, logged, or surfaced by higher-level tooling, allowing anyone with access to the output to reuse the key against the AIsa API.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares access to environment secrets and makes external network calls, but it does not define any explicit tool scope or permission boundaries. In an agent ecosystem, this weakens least-privilege controls and can allow broader-than-expected access to secrets and outbound communication, increasing the blast radius if the skill is misused or compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs agents to pass local workspace file paths and tweet content to a relay backend at an external domain, but it does not require a clear user-facing disclosure that those local files and post contents will be transmitted off-host. In an agent setting, this can cause users to unknowingly send sensitive media or text to a third-party service, especially when attachments originate from the local workspace and may contain private data.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/post_twitter.md (reported line 86)May include surrounding context.

md
## Guardrails

- Do not ask the user for their Twitter password.
- Do not use cookie-based login or proxy-based login unless the user explicitly asks for legacy behavior.
- Do not default to `--open-browser`; return the authorization link unless the user explicitly wants local browser launch.
- Do not invent remote URLs for attachments; always use the provided local workspace file path with `--media-file`.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1"
DEFAULT_CHROME_USER_AGENT = (
    "Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
    "AppleWebKit/537.36 (KHTML, like Gecko) "

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/twitter_client.py (reported line 35)May include surrounding context.

python
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1"
DEFAULT_CHROME_USER_AGENT = (
    "Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
    "AppleWebKit/537.36 (KHTML, like Gecko) "

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/twitter_oauth_client.py (reported line 29)May include surrounding context.

python
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1"
DEFAULT_CHROME_USER_AGENT = (
    "Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
    "AppleWebKit/537.36 (KHTML, like Gecko) "

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The post command reads local media files and sends post text, media IDs, and file contents to the remote AIsa service via HTTP requests, but this command path provides no explicit user-facing disclosure before transmission. Although network posting is part of the tool's purpose, the code lacks any warning that local file contents and tweet content are being uploaded to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The authorize flow constructs a payload containing the AISA API key and transmits it to the /twitter/auth_twitter endpoint, but the command does not print or document that credential-bearing data is being sent. There is no confirmation prompt or warning in this file beyond internal code behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.