Back to skill

Security audit

twitter-aisa

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Twitter/X relay purpose, but its posting helper exposes the AIsa API key in command output and can upload local media files without enforcing a workspace boundary.

Review this skill before installing. Use only with a revocable AIsa API key, expect Twitter queries, post text, OAuth requests, and approved media uploads to go to api.aisa.one, and avoid using the posting helper until the raw-key output issue and workspace-boundary check for media files are fixed. Rotate any AISA_API_KEY that may already have appeared in logs or agent transcripts.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/twitter_oauth_client.py:330
Finding

AISA API Key Is Exposed in Command Output and Redundantly Included in Request Bodies

Content
View full analysis
Dict[str, Any]: should_thread = len(chunks) > 1 previous_tweet_id = initial_parent_tweet_id publish_results = [] for index, chunk in enumerate(chunks): current_media_ids = media_ids if index == 0 and media_ids else None current_media_files = media_files if index == 0 and media_files else None result = post_single_tweet( config, content=chunk, media_ids=current_media_ids, media_files=current_media_files, parent_tweet_id=previous_tweet_id, post_type=post_type, ) publish_results.append( { "index": index + 1, "content": chunk, "parent_tweet_id": previous_tweet_id, "result": result, } ) if result.get("ok") is False or result.get("code") != 200: return { "ok": False, "aisa_api_key": config["aisa_api_key"], "is_thread": should_thread, "total_chunks": len(chunks), "failed_at_chunk": index + 1, "results": publish_results, } latest_tweet_id = extract_tweet_id(result) if not latest_tweet_id: return { "ok": False, "aisa_api_key": config["aisa_api_key"], "is_thread": should_t ...[truncated 4106 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/twitter_oauth_client.py:413
Finding

Media Upload Accepts Arbitrary Locally Readable File Paths Without a Workspace Boundary

Content
View full analysis
list[Dict[str, Any]]: if not paths: return [] media_files: list[Dict[str, Any]] = [] media_kinds: set[str] = set() seen_paths: set[str] = set() for raw_path in paths: resolved_path = os.path.abspath(os.path.expanduser(raw_path)) normalized_path = os.path.normcase(resolved_path) if normalized_path in seen_paths: continue seen_paths.add(normalized_path) if not os.path.exists(resolved_path): raise RelayConfigError(f"Media file does not exist: {raw_path}") if not os.path.isfile(resolved_path): raise RelayConfigError(f"Media path is not a file: {raw_path}") mime_type = mimetypes.guess_type(resolved_path)[0] or "application/octet-stream" media_kind = mime_type.split("/", 1)[0] if media_kind not in {"image", "video"}: raise RelayConfigError( f"Unsupported media type for {raw_path}: {mime_type}. Only image and video files are supported." ) media_kinds.add(media_kind) with open(resolved_path, "rb") as file_handle: content = file_handle.read() media_files.append( { "field_name": "media_files", "filename": os.path.basename(resolved_path), "content_type": mime_type, "content": content, } ) if len(media_kinds) > 1: raise RelayConfigError("Do not mix image and video files in a single post request.") return media_files ``` The resulting file content is sent to the external relay: ```python if media_files: return send_multipart_request( endpoint, payload, ...[truncated 2934 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This finding indicates the skill is presented as a broad Twitter command center for research and monitoring, while the actual code is reportedly much narrower and does not provide the advertised monitoring, trend tracking, or watchlist behavior. Such overclaiming is dangerous because users may route sensitive operational tasks through the skill under false assumptions about its controls, completeness, or approval model.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This finding indicates the skill is presented as a broad Twitter command center for research and monitoring, while the actual code is reportedly much narrower and does not provide the advertised monitoring, trend tracking, or watchlist behavior. Such overclaiming is dangerous because users may route sensitive operational tasks through the skill under false assumptions about its controls, completeness, or approval model.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The post operation returns and prints the raw API key in normal and failure output paths. This turns every tweet publish into a potential secret disclosure event and could enable anyone with access to captured output to impersonate the client against the AIsa API.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares required environment access and relay-based network use but does not define an explicit tool scope such as permissions or allowed-tools. In agent ecosystems, this can lead to overbroad execution privileges, unclear operator expectations, and accidental exposure of secrets like AISA_API_KEY to code paths or tools beyond what is necessary.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/post_twitter.md (reported line 86)May include surrounding context.

md
## Guardrails

- Do not ask the user for their Twitter password.
- Do not use cookie-based login or proxy-based login unless the user explicitly asks for legacy behavior.
- Do not default to `--open-browser`; return the authorization link unless the user explicitly wants local browser launch.
- Do not invent remote URLs for attachments; always use the provided local workspace file path with `--media-file`.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code sends usernames, tweet IDs, search queries, and similar inputs to the remote service at api.aisa.one via HTTP requests. Although the module docstring states that it is a Twitter/X API client, there is no runtime disclosure, confirmation, or explicit privacy warning that user-provided inputs are transmitted to a third-party endpoint.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/twitter_client.py (reported line 35)May include surrounding context.

python
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1"
DEFAULT_CHROME_USER_AGENT = (
    "Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
    "AppleWebKit/537.36 (KHTML, like Gecko) "

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/twitter_oauth_client.py (reported line 29)May include surrounding context.

python
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1"
DEFAULT_CHROME_USER_AGENT = (
    "Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
    "AppleWebKit/537.36 (KHTML, like Gecko) "

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The client includes the full AIsa API key in the returned post result structure, and command_post prints that structure to stdout. This can leak a bearer credential into terminal scrollback, shell history wrappers, logs, CI output, or any calling agent that captures stdout, allowing unauthorized use of the AIsa API.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The authorization command prints the full API key alongside the authorization URL. Because this is an OAuth helper likely to be run interactively or by tooling, exposing the bearer token in stdout materially increases the chance of credential disclosure to logs, transcripts, or other local users/processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The authorization flow outputs sensitive API key material directly in command results, creating the same leakage channel as other stdout exposure issues. OAuth-related commands are especially likely to be copied into support tickets or automation logs, amplifying the credential exposure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file performs a network operation that transmits user-provided tweet content and optional media files to the AIsa service via publish_chunks/post_single_tweet, then only prints the result after the fact. Although the CLI help says it publishes through the AIsa service, there is no explicit runtime warning, confirmation, or privacy disclosure when sending user data and local file contents to the remote endpoint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.