T09 · Insecure Skill Coding Practices
- Location
scripts/twitter_oauth_client.py:337- Finding
AISA API Key Disclosed in Command Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s Twitter/X research and posting purpose is coherent, but it exposes the configured API key in normal command output and allows posting/auth requests to be redirected to arbitrary HTTP or HTTPS relay URLs.
Review this skill before installing. It is not clearly malicious, but only use it with a low-privilege, revocable AISA_API_KEY, avoid running status/authorize/post in logs or shared transcripts until key echoing is fixed, do not set TWITTER_RELAY_BASE_URL to untrusted or plaintext HTTP hosts, and require explicit approval before any post or media upload is published.
scripts/twitter_oauth_client.py:337AISA API Key Disclosed in Command Output
scripts/twitter_oauth_client.py:44API Key and Posting Data Can Be Sent to an Arbitrary Plaintext Relay
The description claims OAuth-gated posting and a narrower Twitter research scope, while the analyzed behavior indicates posting may not be implemented and additional read capabilities exist beyond what is clearly disclosed. This mismatch can mislead users or orchestration layers about what the skill actually does, causing inappropriate invocation, overcollection of data, or trust in controls that are not present.
The description claims OAuth-gated posting and a narrower Twitter research scope, while the analyzed behavior indicates posting may not be implemented and additional read capabilities exist beyond what is clearly disclosed. This mismatch can mislead users or orchestration layers about what the skill actually does, causing inappropriate invocation, overcollection of data, or trust in controls that are not present.
The skill declares required environment access and implies networked API usage, but it does not declare an explicit tool scope such as allowed-tools or permissions. That weakens policy enforcement and makes it harder for an agent runtime to constrain what the skill may access, increasing the chance of unintended secret exposure or broader-than-expected external communication.
A broad invocation description can cause the agent to select this skill for generic social-media requests, even when a narrower or safer skill would be more appropriate. Because this skill has network access and can interact with external services, overbroad routing increases the chance of unnecessary API use, unintended data disclosure, or actions taken in the wrong context.
The 'When to use' guidance is expansive and lacks clear constraints such as requiring Twitter/X specificity, user intent confirmation for monitoring, or explicit approval before any write action. In an agent ecosystem, overly broad trigger language can lead to accidental invocation and unnecessary collection or use of external account data.
The skill supports autonomous posting to a real X/Twitter account, including attached local media, but does not clearly warn that execution will publish content publicly under the user’s identity. In an agentic context, this omission can lead to users authorizing or triggering actions without fully understanding the privacy, reputational, and data exposure consequences.
The skill’s agent instructions say to default all publishing to --type quote, which conflicts with earlier documented behavior stating that normal standalone posts should not send relationship fields and that quote mode requires an explicit target tweet URL. This can cause unintended quote-post behavior, broken publish attempts, or accidental inclusion of relationship metadata the user did not request, increasing the risk of incorrect public posting on the user's account.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Guardrails
- Do not ask the user for their Twitter password.
- Do not use cookie-based login or proxy-based login unless the user explicitly asks for legacy behavior.
- Do not claim authorization succeeded just because an authorization URL was generated.
- Do not ask for a tweet link or tweet ID just because the user requested `reply`; use `--type reply` directly.
The file presents itself as a read-only Twitter/X client, but the shared request helper supports POST and automatically injects the API key into POST bodies. That mismatch is dangerous in an agent setting because downstream code or future modifications may invoke state-changing endpoints while operators believe the tool is safe for read-only use, and placing credentials in request bodies increases exposure through logs, proxies, and upstream services.
The inline documentation repeatedly frames the client as read-only, while the code contains generic POST behavior. In an autonomous agent skill, this kind of capability/documentation mismatch weakens security review, approval, and user consent because higher-privilege actions can be hidden behind a seemingly harmless interface.
This code file sends usernames, tweet IDs, search queries, and related parameters to a remote service at api.aisa.one, and authenticates using an environment-sourced API key. While the module docstring mentions read APIs and bearer auth, there is no runtime confirmation, user-facing disclosure, or warning that user inputs and account lookups will be transmitted off-system to a third-party endpoint.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1"
DEFAULT_CHROME_USER_AGENT = (
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
"AppleWebKit/537.36 (KHTML, like Gecko) "
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1"
DEFAULT_CHROME_USER_AGENT = (
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
"AppleWebKit/537.36 (KHTML, like Gecko) "
The client includes the raw AISA API key in post-related command output, which can expose a bearer credential to terminals, logs, chat transcripts, CI output, or any downstream tooling that captures stdout. Because this key authorizes calls to the relay service, disclosure can enable unauthorized use of the account and relay endpoints beyond the immediate Twitter action.
Authorization and post command results include the API key in normal JSON output, which can leak secrets during common workflows rather than only in debug mode. Since these commands are likely to be invoked by automation or agent frameworks, the exposed key may propagate into logs and reusable transcripts where attackers or other users can retrieve it.
The authorization/status flows echo the full API key back to the user even though it is only needed for authentication to the relay. Exposing long-lived bearer material during routine status checks increases the chance of accidental credential leakage through shell history captures, screenshots, notebook output, agent logs, or shared terminals.
The status command reveals the complete API key without masking or warning, turning a low-risk diagnostics command into a secret disclosure primitive. In agent or multi-user environments, status output is especially likely to be captured automatically, making credential compromise more likely.
No suspicious patterns detected.