Back to skill

Security audit

Twitter Command Center Search Post

Security checks for vulnerabilities and agentic risk

Overview

The skill’s Twitter/X research and posting purpose is coherent, but it exposes the configured API key in normal command output and allows posting/auth requests to be redirected to arbitrary HTTP or HTTPS relay URLs.

Review this skill before installing. It is not clearly malicious, but only use it with a low-privilege, revocable AISA_API_KEY, avoid running status/authorize/post in logs or shared transcripts until key echoing is fixed, do not set TWITTER_RELAY_BASE_URL to untrusted or plaintext HTTP hosts, and require explicit approval before any post or media upload is published.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/twitter_oauth_client.py:337
Finding

AISA API Key Disclosed in Command Output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/twitter_oauth_client.py:44
Finding

API Key and Posting Data Can Be Sent to an Arbitrary Plaintext Relay

Content
View full analysis
str: value = base_url.strip().rstrip("/") if not value: raise RelayConfigError("TWITTER_RELAY_BASE_URL is required.") parsed = urllib.parse.urlparse(value) if parsed.scheme not in {"http", "https"} or not parsed.netloc: raise RelayConfigError("TWITTER_RELAY_BASE_URL must be a valid http(s) URL.") return value ``` The destination is controlled through an environment variable: ```python def load_config(args: argparse.Namespace) -> Dict[str, Any]: base_url = normalize_base_url( get_env("TWITTER_RELAY_BASE_URL", DEFAULT_BASE_URL) ) aisa_api_key = getattr(args, "aisa_api_key", None) or get_env("AISA_API_KEY") timeout = getattr(args, "timeout", None) or int(get_env("TWITTER_RELAY_TIMEOUT", str(DEFAULT_TIMEOUT))) if not aisa_api_key: raise RelayConfigError("AISA_API_KEY is required.") return { "base_url": base_url, "aisa_api_key": aisa_api_key, "timeout": timeout, } ``` The API key is sent in the authorization header: ```python def build_auth_headers(aisa_api_key: str, extra_headers: Optional[Dict[str, str]] = None) -> Dict[str, str]: headers = { "Authorization": f"Bearer {aisa_api_key}", "User-Agent": DEFAULT_CHROME_USER_AGENT, } if extra_headers: headers.update(extra_headers) return headers ``` Posting requests duplicate the key in the request bod ...[truncated 3845 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The description claims OAuth-gated posting and a narrower Twitter research scope, while the analyzed behavior indicates posting may not be implemented and additional read capabilities exist beyond what is clearly disclosed. This mismatch can mislead users or orchestration layers about what the skill actually does, causing inappropriate invocation, overcollection of data, or trust in controls that are not present.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description claims OAuth-gated posting and a narrower Twitter research scope, while the analyzed behavior indicates posting may not be implemented and additional read capabilities exist beyond what is clearly disclosed. This mismatch can mislead users or orchestration layers about what the skill actually does, causing inappropriate invocation, overcollection of data, or trust in controls that are not present.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares required environment access and implies networked API usage, but it does not declare an explicit tool scope such as allowed-tools or permissions. That weakens policy enforcement and makes it harder for an agent runtime to constrain what the skill may access, increasing the chance of unintended secret exposure or broader-than-expected external communication.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

A broad invocation description can cause the agent to select this skill for generic social-media requests, even when a narrower or safer skill would be more appropriate. Because this skill has network access and can interact with external services, overbroad routing increases the chance of unnecessary API use, unintended data disclosure, or actions taken in the wrong context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The 'When to use' guidance is expansive and lacks clear constraints such as requiring Twitter/X specificity, user intent confirmation for monitoring, or explicit approval before any write action. In an agent ecosystem, overly broad trigger language can lead to accidental invocation and unnecessary collection or use of external account data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill supports autonomous posting to a real X/Twitter account, including attached local media, but does not clearly warn that execution will publish content publicly under the user’s identity. In an agentic context, this omission can lead to users authorizing or triggering actions without fully understanding the privacy, reputational, and data exposure consequences.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill’s agent instructions say to default all publishing to --type quote, which conflicts with earlier documented behavior stating that normal standalone posts should not send relationship fields and that quote mode requires an explicit target tweet URL. This can cause unintended quote-post behavior, broken publish attempts, or accidental inclusion of relationship metadata the user did not request, increasing the risk of incorrect public posting on the user's account.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/post_twitter.md (reported line 147)May include surrounding context.

md
## Guardrails

- Do not ask the user for their Twitter password.
- Do not use cookie-based login or proxy-based login unless the user explicitly asks for legacy behavior.
- Do not claim authorization succeeded just because an authorization URL was generated.
- Do not ask for a tweet link or tweet ID just because the user requested `reply`; use `--type reply` directly.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file presents itself as a read-only Twitter/X client, but the shared request helper supports POST and automatically injects the API key into POST bodies. That mismatch is dangerous in an agent setting because downstream code or future modifications may invoke state-changing endpoints while operators believe the tool is safe for read-only use, and placing credentials in request bodies increases exposure through logs, proxies, and upstream services.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The inline documentation repeatedly frames the client as read-only, while the code contains generic POST behavior. In an autonomous agent skill, this kind of capability/documentation mismatch weakens security review, approval, and user consent because higher-privilege actions can be hidden behind a seemingly harmless interface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file sends usernames, tweet IDs, search queries, and related parameters to a remote service at api.aisa.one, and authenticates using an environment-sourced API key. While the module docstring mentions read APIs and bearer auth, there is no runtime confirmation, user-facing disclosure, or warning that user inputs and account lookups will be transmitted off-system to a third-party endpoint.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/twitter_client.py (reported line 36)May include surrounding context.

python
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1"
DEFAULT_CHROME_USER_AGENT = (
    "Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
    "AppleWebKit/537.36 (KHTML, like Gecko) "

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/twitter_oauth_client.py (reported line 27)May include surrounding context.

python
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1"
DEFAULT_CHROME_USER_AGENT = (
    "Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
    "AppleWebKit/537.36 (KHTML, like Gecko) "

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The client includes the raw AISA API key in post-related command output, which can expose a bearer credential to terminals, logs, chat transcripts, CI output, or any downstream tooling that captures stdout. Because this key authorizes calls to the relay service, disclosure can enable unauthorized use of the account and relay endpoints beyond the immediate Twitter action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Authorization and post command results include the API key in normal JSON output, which can leak secrets during common workflows rather than only in debug mode. Since these commands are likely to be invoked by automation or agent frameworks, the exposed key may propagate into logs and reusable transcripts where attackers or other users can retrieve it.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The authorization/status flows echo the full API key back to the user even though it is only needed for authentication to the relay. Exposing long-lived bearer material during routine status checks increases the chance of accidental credential leakage through shell history captures, screenshots, notebook output, agent logs, or shared terminals.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The status command reveals the complete API key without masking or warning, turning a low-risk diagnostics command into a secret disclosure primitive. In agent or multi-user environments, status output is especially likely to be captured automatically, making credential compromise more likely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.