Back to skill

Security audit

Twitter Autopilot

Security checks for vulnerabilities and agentic risk

Overview

The skill largely matches its Twitter/X automation purpose, but it exposes the configured AIsa API key in normal outputs and can send that key plus user content to a configurable relay.

Review before installing. Do not run status, authorize, or post with a real AISA_API_KEY unless the package is fixed to redact secrets. Avoid setting TWITTER_RELAY_BASE_URL to any non-default or HTTP endpoint, and use a dedicated low-privilege/rotatable API key. Treat posting, likes, follows, and OAuth authorization as public account-changing actions that should be explicitly approved each time.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/twitter_oauth_client.py:337
Finding

API Key Disclosed in Command Output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/twitter_oauth_client.py:44
Finding

Arbitrary HTTP Relay Configuration Can Exfiltrate Credentials and User Content

Content
View full analysis
str: value = base_url.strip().rstrip("/") if not value: raise RelayConfigError("TWITTER_RELAY_BASE_URL is required.") parsed = urllib.parse.urlparse(value) if parsed.scheme not in {"http", "https"} or not parsed.netloc: raise RelayConfigError("TWITTER_RELAY_BASE_URL must be a valid http(s) URL.") return value ``` ```python # scripts/twitter_oauth_client.py:55-67 def load_config(args: argparse.Namespace) -> Dict[str, Any]: base_url = normalize_base_url( get_env("TWITTER_RELAY_BASE_URL", DEFAULT_BASE_URL) ) aisa_api_key = getattr(args, "aisa_api_key", None) or get_env("AISA_API_KEY") timeout = getattr(args, "timeout", None) or int(get_env("TWITTER_RELAY_TIMEOUT", str(DEFAULT_TIMEOUT))) if not aisa_api_key: raise RelayConfigError("AISA_API_KEY is required.") return { "base_url": base_url, "aisa_api_key": aisa_api_key, "timeout": timeout, } ``` ```python # scripts/twitter_oauth_client.py:78-105 def build_auth_headers(aisa_api_key: str, extra_headers: Optional[Dict[str, str]] = None) -> Dict[str, str]: headers = { "Authorization": f"Bearer {aisa_api_key}", "User-Agent": DEFAULT_CHROME_USER_AGENT, } if extra_headers: headers.update(extra_head ...[truncated 5278 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (51)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The finding indicates the skill may expose configuration or status details, including relay URL and possibly API-key-related state, without clearly documenting that behavior. Misleading capability descriptions combined with undisclosed configuration exposure can cause operators to invoke the skill without understanding what metadata or secrets might be revealed or where actions are actually routed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The finding indicates the skill may expose configuration or status details, including relay URL and possibly API-key-related state, without clearly documenting that behavior. Misleading capability descriptions combined with undisclosed configuration exposure can cause operators to invoke the skill without understanding what metadata or secrets might be revealed or where actions are actually routed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The finding indicates the skill may expose configuration or status details, including relay URL and possibly API-key-related state, without clearly documenting that behavior. Misleading capability descriptions combined with undisclosed configuration exposure can cause operators to invoke the skill without understanding what metadata or secrets might be revealed or where actions are actually routed.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

This is a direct secret disclosure: the script returns the configured API key in standard successful output rather than only in protected internal state. Because this skill performs authenticated engagement actions like liking and following through relay endpoints, disclosure is especially dangerous: anyone with output access may gain the same capability without needing the user's OAuth flow.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Publishing results include the full API key, so every successful or failed post can leak the credential to users, logs, orchestration layers, or observability systems. Since posting is a common operation, this amplifies exposure frequency and makes credential theft more likely.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Authorization and posting flows include the full AISA API key in routine command results, causing credential exposure during normal operation. Because agent tools often log or relay command output, this creates a practical secret-leak path that can enable unauthorized use of the relay backend.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises capabilities that can change a user's X account state—posting, liking, and following—without any nearby warning that these are user-impacting actions requiring explicit confirmation and careful use. In an agent-skill context, underemphasizing side effects increases the risk of accidental or overbroad account actions, especially because OAuth-enabled access can make those operations immediately executable once authorized.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares network and environment-variable usage but does not define an explicit tool scope such as allowed tools or permissions. In an agent setting, this weakens least-privilege enforcement and makes it easier for the skill to access secrets and perform outbound requests beyond what a reviewer or runtime may expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill enables account-affecting actions such as posting, liking, and following but does not present an explicit warning about irreversible or reputation-affecting social actions. In an agent workflow, this increases the risk of unintended posts or engagement on behalf of a user, especially if confirmation boundaries are weak.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/engage_twitter.md (reported line 64)May include surrounding context.

md
When the user asks to like, unlike, follow, or unfollow on X/Twitter:

1. Do not ask the user for tweet IDs, tweet links, or user IDs.
2. If the user specifies a direct account such as `@elonmusk`, call the `--user` based command.
3. If the user asks for the latest tweet, use `like-latest` or `unlike-latest`.
4. If the user first asked to query tweets, keep the returned `tweets[]` structure in agent context.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/engage_twitter.md (reported line 76)May include surrounding context.

md
When the user asks to like, unlike, follow, or unfollow on X/Twitter:

1. Do not ask the user for tweet IDs, tweet links, or user IDs.
2. If the user specifies a direct account such as `@elonmusk`, call the `--user` based command.
3. If the user asks for the latest tweet, use `like-latest` or `unlike-latest`.
4. If the user first asked to query tweets, keep the returned `tweets[]` structure in agent context.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/post_twitter.md (reported line 147)May include surrounding context.

md
When the user asks to like, unlike, follow, or unfollow on X/Twitter:

1. Do not ask the user for tweet IDs, tweet links, or user IDs.
2. If the user specifies a direct account such as `@elonmusk`, call the `--user` based command.
3. If the user asks for the latest tweet, use `like-latest` or `unlike-latest`.
4. If the user first asked to query tweets, keep the returned `tweets[]` structure in agent context.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill supports posting, liking, and following on a real user-linked X/Twitter account, but the instructions shown do not prominently warn that these actions create public, account-level side effects. In this context, insufficient disclosure can lead users to authorize or trigger actions without appreciating that the agent may publish publicly under their identity.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to default all publishing to --type quote, which conflicts with earlier guidance that normal standalone posts should not send quote/reply relationship fields. In a posting skill, this can cause unintended quote-tweets, altered post semantics, or malformed publishing behavior without the user's explicit intent, increasing the risk of accidental public interactions on the user's account.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module advertises itself as read-only, but the shared request helper supports POST and automatically injects the API key into POST bodies. That mismatch is dangerous because downstream agents or reviewers may trust the documentation and permit use in contexts intended to be non-mutating, while hidden write-capable behavior could enable unintended state changes or broader credential exposure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation states that read APIs use GET, yet the implementation contains explicit POST handling that adds the API key to the JSON body. Even though no POST call sites are exposed in this file today, the hidden capability creates a misleading trust boundary and increases the risk of future side-effecting use or credential leakage through body logging at intermediaries.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The status command includes the configured aisa_api_key in normal JSON output, which discloses a live secret to any caller who can invoke the script or capture its output. In this skill context, that key is used to access Twitter/X relay functionality, so exposing it can enable unauthorized API use, abuse of the relay, and lateral reuse if the same key is trusted elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The command exposes the API key without masking or any warning, increasing the chance that users, logs, shell history, orchestration layers, or calling agents will inadvertently store or forward the secret. Even if intended for diagnostics, unguarded disclosure of a credential violates least exposure and makes downstream leakage much more likely.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1/twitter"
DEFAULT_CHROME_USER_AGENT = (
    "Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
    "AppleWebKit/537.36 (KHTML, like Gecko) "

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

md
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1/twitter"
DEFAULT_CHROME_USER_AGENT = (
    "Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
    "AppleWebKit/537.36 (KHTML, like Gecko) "

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

md
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1/twitter"
DEFAULT_CHROME_USER_AGENT = (
    "Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
    "AppleWebKit/537.36 (KHTML, like Gecko) "

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1/twitter"
DEFAULT_CHROME_USER_AGENT = (
    "Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
    "AppleWebKit/537.36 (KHTML, like Gecko) "

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

md
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1/twitter"
DEFAULT_CHROME_USER_AGENT = (
    "Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
    "AppleWebKit/537.36 (KHTML, like Gecko) "

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

md
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1/twitter"
DEFAULT_CHROME_USER_AGENT = (
    "Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
    "AppleWebKit/537.36 (KHTML, like Gecko) "

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

md
DEFAULT_TIMEOUT = 30
DEFAULT_BASE_URL = "https://api.aisa.one/apis/v1/twitter"
DEFAULT_CHROME_USER_AGENT = (
    "Mozilla/5.0 (Windows NT 10.0; Win64; x64) "
    "AppleWebKit/537.36 (KHTML, like Gecko) "

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/twitter_engagement_client.py:304