Back to skill

Security audit

Twitter Automation Suite

Security checks for vulnerabilities and agentic risk

Overview

This skill can log into and post from a Twitter/X account, but its broad claims, password-based setup, mutable install process, and disabled browser sandbox warrant review before use.

Install only if you are comfortable giving the skill direct Twitter/X login credentials and letting it post publicly from that account. Use a dedicated low-privilege account if possible, avoid exposing unrelated secrets in the same environment, review posts before sending, pin dependencies with a lockfile, and do not run the browser automation with sandboxing disabled outside an isolated environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/post.js:28
Finding

Chromium Security Sandbox Disabled During Authenticated Browser Automation

Content
View full analysis

Vulnerability Details

File Location: scripts/post.js, lines 28-31
Vulnerability Type: Chromium sandbox bypass configuration
Risk Level: High

Complete Code Snippet:

javascript
this.browser = await puppeteer.launch({
  headless: false,
  args: ['--no-sandbox', '--disable-setuid-sandbox']
});

Technical Analysis

The Puppeteer-controlled Chromium process is launched with both --no-sandbox and --disable-setuid-sandbox. These options disable browser security boundaries intended to isolate renderers and other browser subprocesses from the host environment.

The browser loads remote Twitter content while the Node.js process has access to Twitter credentials from environment variables. Browser content can also include user-controlled posts, advertisements, media, and third-party resources. If any loaded content exploits a Chromium vulnerability, disabling the sandbox substantially reduces the isolation barriers that would otherwise constrain the compromised renderer.

This finding does not demonstrate an embedded browser exploit in the project. Exploitation depends on a separate Chromium vulnerability or compromised remote content, but the configuration materially increases the consequences of such an event.

Attack Path

  1. A user invokes the posting feature.
  2. The skill launches Chromium with its sandbox disabled.
  3. Chromium authenticates to Twitter and processes remote content under the account session.
  4. Attacker-controlled or compromised remote content triggers a compatible Chromium vulnerability.
  5. Because the browser sandbox is disabled, the malicious browser code may reach host resources with the privileges of the user running the Node.js process.
  6. The attacker may then access files, environment data, browser session state, or other resources available to that operating-system account.

Impact Assessment

Successful exploitation could allow code execution with the pr ...[truncated 593 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove both sandbox-disabling arguments:
    javascript
    this.browser = await puppeteer.launch({
      headless: false
    });
    
  2. Run Chromium as a non-root user with functional user namespaces and the standard Chromium sandbox enabled.
  3. If the deployment platform cannot support the sandbox, correct the container or host configuration rather than disabling browser isolation.
  4. As defense in depth, run browser automation in a disposable, hardened container with:
    • A non-root user.
    • A read-only root filesystem.
    • No host filesystem mounts except explicitly required files.
    • Dropped Linux capabilities.
    • Resource limits and a restrictive seccomp or equivalent policy.
    • Network access restricted to required Twitter endpoints.
  5. Supply account credentials only to the isolated process and avoid exposing unrelated secrets in its environment.
  6. Keep Puppeteer and the bundled Chromium version patched to reduce exposure to known browser vulnerabilities.

T08 · Insecure Dependencies

Warning
Location
package.json:16
Finding

Unpinned Dependency Resolution Without a Lockfile

Content
View full analysis

Vulnerability Details

File Location: package.json, lines 16-21; related installation instructions in SKILL.md, lines 29-32
Vulnerability Type: Unsafe and non-reproducible third-party dependency installation
Risk Level: Medium

Complete Code Snippet:

json
"dependencies": {
  "puppeteer": "^21.0.0",
  "twitter-api-v2": "^1.15.0",
  "dotenv": "^16.3.0",
  "node-cron": "^3.0.0"
}

Related installation instruction:

bash
npm install puppeteer playwright twitter-api-v2 dotenv

Technical Analysis

The dependency declarations use caret version ranges, and no package lockfile was present in the audited project. Consequently, separate installations can resolve different transitive and direct package versions without a reviewed, reproducible dependency graph.

The documentation further instructs users to run an installation command with unpinned package names. It includes playwright, although that package is not declared in package.json, and omits node-cron, which is declared. This inconsistency expands the installed dependency set beyond the manifest and makes review of the effective supply chain more difficult.

npm dependencies can contain lifecycle scripts that execute during installation. If a permitted package release, transitive dependency, or package-maintainer account is compromised, a future installation could execute malicious code with the privileges of the user running npm. The audit found no evidence that the currently named packages are intentionally malicious; the issue is the mutable and unreproducible installation process.

Attack Path

  1. An attacker compromises a dependency publisher, an allowed future release, or a transitive dependency in the permitted version graph.
  2. A user follows the documented command or performs a fresh installation without a reviewed lockfile.
  3. npm resolves the affected mutable package version.
  4. Malicious lifecycle code may ...[truncated 929 chars]
Remediation
View remediation

Remediation Suggestions

  1. Generate and commit a reviewed package-lock.json.
  2. Use npm ci in automated and production installations so dependency resolution follows the committed lockfile.
  3. Pin direct dependencies to exact reviewed versions where operationally practical.
  4. Update the documentation to instruct users to install from the manifest rather than naming packages individually:
    bash
    npm ci
    
  5. Remove playwright from the instructions unless it is genuinely required and formally declared.
  6. Remove unused dependencies from package.json, including node-cron if scheduling is not implemented.
  7. Review dependency updates before regenerating the lockfile and use automated vulnerability and provenance checks.
  8. Perform dependency installation in a restricted build environment without production secrets.
  9. Consider disabling lifecycle scripts during review or build stages when compatible:
    bash
    npm ci --ignore-scripts
    
    If lifecycle scripts are required, explicitly audit and allow only the necessary scripts.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description presents a broader Twitter/X automation toolkit with multiple capabilities: automatic posting, keyword monitoring, bulk replies, and AI content generation. However, the supplied code only implements browser automation for logging into Twitter/X and posting tweets, optionally with an image or as a thread. There is no code for monitoring keywords, scanning timelines/search results, replying to multiple posts, or generating content with AI. The code's actual behavior is a narrower posting utility rather than the fuller automation suite described. This is a description-behavior mismatch due to materially overstated capabilities in the description relative to the provided code chunk.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · index.js (reported line 47)May include surrounding context.

js
const params = args.slice(1);

  // 检查环境变量
  if (!fs.existsSync('.env')) {
    console.log('⚠️  请先创建 .env 文件并配置 Twitter 账号信息');
    console.log('复制 .env.example 文件并填写你的信息');
    return;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · index.js (reported line 48)May include surrounding context.

js
// 检查环境变量
  if (!fs.existsSync('.env')) {
    console.log('⚠️  请先创建 .env 文件并配置 Twitter 账号信息');
    console.log('复制 .env.example 文件并填写你的信息');
    return;
  }

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs users to configure sensitive credentials in environment variables, including a Twitter password and email, but does not declare any explicit tool scope or permissions. This creates an opaque trust boundary: a runtime may expose environment access implicitly, allowing credential handling without clear user consent or sandbox policy, which increases the risk of secret misuse or unintended exfiltration in an automation skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and all example commands are written in Chinese, and the skill provides no indication that other languages are supported or that the Chinese-only behavior is optional. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The user-facing description and command output throughout the file are entirely in Chinese, indicating a fixed language/locale for the skill experience. The file does not provide any opt-in, fallback, or documented justification for requiring Chinese, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This manifest file uses a general description for a Twitter/X automation suite covering posting, monitoring, replying, and analysis, but it does not define specific trigger phrases, scope boundaries, or exclusion conditions. In a manifest context, such broad wording can lead to unintended invocation for generic social-media-related requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's natural-language strings and description are entirely in Chinese, including operational logs and error messages, but there is no indication that the skill is region-specific or that users can opt into this locale. That creates a language/locale policy concern because the skill effectively forces one language for interaction and troubleshooting.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description is written entirely in Chinese and does not indicate that language selection is optional or that the skill is intended only for a Chinese-speaking context. This can conflict with language or locale policy expectations when no user opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
91% confidence
Finding

Using a caret range for puppeteer allows installation of newer releases within the major version without explicit review, which weakens supply-chain control and reproducibility. In a browser-automation skill that can log into social platforms and manipulate sessions, an unexpected dependency update could introduce malicious code or a vulnerable transitive package with meaningful account-impact.

Content

Scanner excerpt · package.json (reported line 17)May include surrounding context.

json
"author": "",
  "license": "MIT",
  "dependencies": {
    "puppeteer": "^21.0.0",
    "twitter-api-v2": "^1.15.0",
    "dotenv": "^16.3.0",
    "node-cron": "^3.0.0"

Unverifiable Dependency: puppeteer has 1 known advisory(ies) (CVE-2019-5786 (Use-After-Free in puppeteer)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
89% confidence
Finding

The twitter-api-v2 dependency is not pinned to an exact version, so future installs may resolve to different code than was tested. Because this library likely handles Twitter/X authentication and API actions, an unreviewed update could affect token handling, posting behavior, or introduce supply-chain risk.

Content

Scanner excerpt · package.json (reported line 18)May include surrounding context.

json
"license": "MIT",
  "dependencies": {
    "puppeteer": "^21.0.0",
    "twitter-api-v2": "^1.15.0",
    "dotenv": "^16.3.0",
    "node-cron": "^3.0.0"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
84% confidence
Finding

The dotenv package is specified with a version range, allowing silent drift across installations. Although lower impact than browser or API automation libraries, configuration-loading packages often touch secrets, so reproducibility and integrity still matter.

Content

Scanner excerpt · package.json (reported line 19)May include surrounding context.

json
"dependencies": {
    "puppeteer": "^21.0.0",
    "twitter-api-v2": "^1.15.0",
    "dotenv": "^16.3.0",
    "node-cron": "^3.0.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
84% confidence
Finding

The node-cron dependency is unpinned, creating avoidable supply-chain and reproducibility risk. In an automation suite, scheduled execution can amplify the effect of a compromised or buggy dependency by repeatedly running unattended tasks.

Content

Scanner excerpt · package.json (reported line 20)May include surrounding context.

json
"puppeteer": "^21.0.0",
    "twitter-api-v2": "^1.15.0",
    "dotenv": "^16.3.0",
    "node-cron": "^3.0.0"
  }
}

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:85