Back to skill

Security audit

Twitter Daily Digest

Security checks for vulnerabilities and agentic risk

Overview

This Twitter/X digest skill is mostly coherent, but it uses authenticated account access and can automatically persist digest content locally and into Notion without tight scoping or clear confirmation.

Review before installing. Use it only if you want an agent to read your authenticated Twitter/X following activity, write digest files under your home/Desktop area, and publish the finished digest into the configured Notion parent page. Pin and verify twitter-cli, check the Notion parent page and API key scope, and require explicit confirmation before any Notion sync.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:17
Finding

Unpinned Third-Party Twitter CLI Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17–19
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code Snippet:

markdown
- 已安装并认证 twitter CLI
  - 包名:`twitter-cli`
  - 安装命令:`uv tool install twitter-cli`

Technical Analysis

The documented installation command installs twitter-cli without specifying a reviewed version, lockfile, package hash, trusted publisher, or explicit package index. Consequently, the dependency resolved during installation can differ from the version originally reviewed.

This CLI is security-sensitive because the Skill executes it to access an authenticated Twitter/X account. A compromised package release, dependency-confusion event, or malicious package substitution could therefore execute arbitrary code with the privileges of the user running the Agent. The project itself does not download and execute a remote payload at runtime; the risk arises specifically during installation or upgrade of the unpinned dependency.

Attack Path

  1. An attacker compromises the package distribution account or otherwise causes a malicious twitter-cli release to be resolved by the configured package index.
  2. The user or Agent follows the documented command uv tool install twitter-cli.
  3. Because no version or integrity constraint is supplied, the package manager installs the attacker-controlled release.
  4. The Skill invokes the installed twitter executable during whoami, following, or user-posts operations.
  5. The malicious executable runs under the Agent user's operating-system account and within the authenticated Twitter context.
  6. It can access resources available to that account, tamper with collected data, or disclose accessible credentials and files.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the Agent user. The potential scope includes theft or misus ...[truncated 455 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin twitter-cli to a specifically reviewed version, for example by documenting an exact version constraint.
  2. Use a lockfile or installation mechanism that verifies cryptographic hashes for the package and its transitive dependencies.
  3. Explicitly document the approved package index, package publisher, and expected executable provenance.
  4. Avoid automatic upgrades; review release contents and dependency changes before updating the pin.
  5. Run the CLI under a restricted operating-system account or sandbox with access only to resources required for Twitter collection.
  6. Restrict credential-file permissions and ensure the Twitter CLI cannot read unrelated secrets such as the Notion API key unless required.
  7. Consider verifying the installed executable and package metadata before each use in automated environments.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared behavior says the skill summarizes Twitter activity, but the file also instructs syncing content to Notion and saving markdown locally, while the script itself primarily produces JSON rather than the promised final digest. This mismatch can cause users or orchestrators to authorize the skill under incomplete assumptions, leading to undisclosed third-party data transfer and broader-than-expected side effects.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes shell commands, reads environment/config files, writes local files, and uses networked services, but it declares no explicit tool scope or permission boundaries. This weakens least-privilege controls and makes unintended file access, command execution, or external data exfiltration harder to govern if the skill is triggered unexpectedly or modified later.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include broad everyday language such as '帮我看看推特' and '刷推', which can match casual conversation and cause unintended invocation. Because this skill performs network access, local file writes, and optional Notion sync, accidental activation can lead to unnecessary data collection or external sharing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description states “默认输出中文整合版正文,” and later instructions repeat that the final result should be translated into natural Chinese. This imposes a language preference by default without indicating user choice, opt-in, or a region-specific justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description says it fetches and organizes recent Twitter/X updates, but the code also includes a second capability to sync content into Notion. This scope expansion creates an unexpected data-flow path to a third-party service, increasing privacy and exfiltration risk because users invoking a digest skill may not expect remote publication behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file sets LOCAL_TZ = ZoneInfo("Asia/Shanghai"), causing rendered times and date-based titles to be formatted in a specific locale/timezone regardless of user preference. The docstring also assigns final Chinese editing to downstream processing, reinforcing a China-specific localization choice without offering an opt-in or configuration path.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/fetch_digest.py (reported line 83)May include surrounding context.

python
twitter_bin = find_twitter_binary()
    cmd = [twitter_bin] + args + ["--json"]
    try:
        result = subprocess.run(cmd, capture_output=True, text=True, timeout=timeout)
        if result.returncode != 0:
            stderr = (result.stderr or "").strip()
            print(f"  [warn] command failed: {twitter_bin} {' '.join(args)}", file=sys.stderr)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script reads a local Notion API key from the user's home directory and uses it to make authenticated outbound API requests. Combined with the skill's unrelated Twitter-digest purpose, this creates an unexpected privileged channel that can publish locally sourced or model-generated content to the user's Notion workspace without the narrow scope implied by the skill metadata.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section actively creates Notion pages and uploads digest content, which goes beyond local fetching and summarization. In the context of a Twitter digest skill, that makes the behavior more dangerous because it can silently transmit and persist collected content to an external workspace, potentially including sensitive follow graphs, tweet selections, or edited summaries.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The code performs authenticated transmission to the Notion API, sending generated content and metadata to an external service. In this skill context, external transmission is more dangerous because the advertised purpose is Twitter digesting, not cross-service publication, so users may not anticipate their data being exported off-tool and persisted remotely.

Content

Scanner excerpt · scripts/fetch_digest.py (reported line 531)May include surrounding context.

python
"icon": {"type": "emoji", "emoji": "📰"},
        "children": children,
    }
    return notion_request("POST", "https://api.notion.com/v1/pages", api_key, payload)


NOTION_MAX_CHILDREN = 100

Static analysis

No suspicious patterns detected.