T09 · Insecure Skill Coding Practices
- Location
scripts/twitter_oauth_client.py:337- Finding
API Key Disclosed in Command Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill largely matches its Twitter/X automation purpose, but it exposes the configured AIsa API key in normal outputs and can send that key plus user content to a configurable relay.
Review before installing. Do not run status, authorize, or post with a real AISA_API_KEY unless the package is fixed to redact secrets. Avoid setting TWITTER_RELAY_BASE_URL to any non-default or HTTP endpoint, and use a dedicated low-privilege/rotatable API key. Treat posting, likes, follows, and OAuth authorization as public account-changing actions that should be explicitly approved each time.
scripts/twitter_oauth_client.py:337API Key Disclosed in Command Output
scripts/twitter_oauth_client.py:44Arbitrary HTTP Relay Configuration Can Exfiltrate Credentials and User Content
The finding indicates the skill may expose configuration or status details, including relay URL and possibly API-key-related state, without clearly documenting that behavior. Misleading capability descriptions combined with undisclosed configuration exposure can cause operators to invoke the skill without understanding what metadata or secrets might be revealed or where actions are actually routed.
The finding indicates the skill may expose configuration or status details, including relay URL and possibly API-key-related state, without clearly documenting that behavior. Misleading capability descriptions combined with undisclosed configuration exposure can cause operators to invoke the skill without understanding what metadata or secrets might be revealed or where actions are actually routed.
The finding indicates the skill may expose configuration or status details, including relay URL and possibly API-key-related state, without clearly documenting that behavior. Misleading capability descriptions combined with undisclosed configuration exposure can cause operators to invoke the skill without understanding what metadata or secrets might be revealed or where actions are actually routed.
This is a direct secret disclosure: the script returns the configured API key in standard successful output rather than only in protected internal state. Because this skill performs authenticated engagement actions like liking and following through relay endpoints, disclosure is especially dangerous: anyone with output access may gain the same capability without needing the user's OAuth flow.
Publishing results include the full API key, so every successful or failed post can leak the credential to users, logs, orchestration layers, or observability systems. Since posting is a common operation, this amplifies exposure frequency and makes credential theft more likely.
Authorization and posting flows include the full AISA API key in routine command results, causing credential exposure during normal operation. Because agent tools often log or relay command output, this creates a practical secret-leak path that can enable unauthorized use of the relay backend.
The README advertises capabilities that can change a user's X account state—posting, liking, and following—without any nearby warning that these are user-impacting actions requiring explicit confirmation and careful use. In an agent-skill context, underemphasizing side effects increases the risk of accidental or overbroad account actions, especially because OAuth-enabled access can make those operations immediately executable once authorized.
The skill declares network and environment-variable usage but does not define an explicit tool scope such as allowed tools or permissions. In an agent setting, this weakens least-privilege enforcement and makes it easier for the skill to access secrets and perform outbound requests beyond what a reviewer or runtime may expect.
The skill enables account-affecting actions such as posting, liking, and following but does not present an explicit warning about irreversible or reputation-affecting social actions. In an agent workflow, this increases the risk of unintended posts or engagement on behalf of a user, especially if confirmation boundaries are weak.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
When the user asks to like, unlike, follow, or unfollow on X/Twitter:
1. Do not ask the user for tweet IDs, tweet links, or user IDs.
2. If the user specifies a direct account such as `@elonmusk`, call the `--user` based command.
3. If the user asks for the latest tweet, use `like-latest` or `unlike-latest`.
4. If the user first asked to query tweets, keep the returned `tweets[]` structure in agent context.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
When the user asks to like, unlike, follow, or unfollow on X/Twitter:
1. Do not ask the user for tweet IDs, tweet links, or user IDs.
2. If the user specifies a direct account such as `@elonmusk`, call the `--user` based command.
3. If the user asks for the latest tweet, use `like-latest` or `unlike-latest`.
4. If the user first asked to query tweets, keep the returned `tweets[]` structure in agent context.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
When the user asks to like, unlike, follow, or unfollow on X/Twitter:
1. Do not ask the user for tweet IDs, tweet links, or user IDs.
2. If the user specifies a direct account such as `@elonmusk`, call the `--user` based command.
3. If the user asks for the latest tweet, use `like-latest` or `unlike-latest`.
4. If the user first asked to query tweets, keep the returned `tweets[]` structure in agent context.
The skill supports posting, liking, and following on a real user-linked X/Twitter account, but the instructions shown do not prominently warn that these actions create public, account-level side effects. In this context, insufficient disclosure can lead users to authorize or trigger actions without appreciating that the agent may publish publicly under their identity.
The skill instructs the agent to default all publishing to --type quote, which conflicts with earlier guidance that normal standalone posts should not send quote/reply relationship fields. In a posting skill, this can cause unintended quote-tweets, altered post semantics, or malformed publishing behavior without the user's explicit intent, increasing the risk of accidental public interactions on the user's account.
The module advertises itself as read-only, but the shared request helper supports POST and automatically injects the API key into POST bodies. That mismatch is dangerous because downstream agents or reviewers may trust the documentation and permit use in contexts intended to be non-mutating, while hidden write-capable behavior could enable unintended state changes or broader credential exposure.
The documentation states that read APIs use GET, yet the implementation contains explicit POST handling that adds the API key to the JSON body. Even though no POST call sites are exposed in this file today, the hidden capability creates a misleading trust boundary and increases the risk of future side-effecting use or credential leakage through body logging at intermediaries.
The status command includes the configured aisa_api_key in normal JSON output, which discloses a live secret to any caller who can invoke the script or capture its output. In this skill context, that key is used to access Twitter/X relay functionality, so exposing it can enable unauthorized API use, abuse of the relay, and lateral reuse if the same key is trusted elsewhere.
The command exposes the API key without masking or any warning, increasing the chance that users, logs, shell history, orchestration layers, or calling agents will inadvertently store or forward the secret. Even if intended for diagnostics, unguarded disclosure of a credential violates least exposure and makes downstream leakage much more likely.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1/twitter"
DEFAULT_CHROME_USER_AGENT = (
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
"AppleWebKit/537.36 (KHTML, like Gecko) "
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1/twitter"
DEFAULT_CHROME_USER_AGENT = (
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
"AppleWebKit/537.36 (KHTML, like Gecko) "
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1/twitter"
DEFAULT_CHROME_USER_AGENT = (
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
"AppleWebKit/537.36 (KHTML, like Gecko) "
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1/twitter"
DEFAULT_CHROME_USER_AGENT = (
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
"AppleWebKit/537.36 (KHTML, like Gecko) "
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1/twitter"
DEFAULT_CHROME_USER_AGENT = (
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
"AppleWebKit/537.36 (KHTML, like Gecko) "
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1/twitter"
DEFAULT_CHROME_USER_AGENT = (
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
"AppleWebKit/537.36 (KHTML, like Gecko) "
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1/twitter"
DEFAULT_CHROME_USER_AGENT = (
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
"AppleWebKit/537.36 (KHTML, like Gecko) "
Detected: suspicious.exposed_secret_literal