Back to skill

Security audit

Twitter Search

Security checks for vulnerabilities and agentic risk

Overview

The skill performs the advertised Twitter/X search, but its wrapper unnecessarily evaluates shell startup files and can silently install an unpinned Python package into the user environment.

Review this skill before installing. Use it only if you are comfortable sending Twitter/X search queries and your twitterapi.io key to a third-party API. Avoid the wrapper until it removes `eval`, stops auto-installing dependencies, and stops passing API keys on the command line; prefer a preconfigured virtual environment and an exported `TWITTER_API_KEY`.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run_search.sh:31
Finding

Shell Command Injection Through Unsafe Evaluation of Shell Configuration

Content
View full analysis
/dev/null || true)" fi # Still not set? Try .zshrc if [[ -z "$TWITTER_API_KEY" && -f "$HOME/.zshrc" ]]; then eval "$(grep -E '^export TWITTER_API_KEY=' "$HOME/.zshrc" 2>/dev/null || true)" fi ``` ### Technical Analysis The wrapper extracts text beginning with `export TWITTER_API_KEY=` from `.bashrc` or `.zshrc` and executes the extracted text using `eval`. The regular expression only validates the beginning of the line; it does not constrain the assignment value. Consequently, shell constructs embedded in the value—including command substitution, additional commands, redirections, and function invocations—are interpreted by the active shell. Reading a credential from configuration does not require arbitrary shell evaluation. For example, the following matching line executes a command when processed by the wrapper: ```bash export TWITTER_API_KEY="$(id > /tmp/twitter-search-eval-proof)" ``` The issue expands the wrapper's behavior beyond the minimum privileges required to retrieve an API key. Instead of reading a value, it creates a local command-execution channel. ### Attack Path 1. An attacker, compromised configuration-management process, or malicious package causes a matching line to be placed in `$HOME/.bashrc` or `$HOME/.zshrc`. 2. `TWITTER_API_KEY` is absent from the wrapper's current environment. 3. The user invokes `scripts/run_search.sh`. 4. `grep` selects the attacker-controlled assignment. 5. `eval` interprets command substitutions or other shell syntax ...[truncated 789 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/run_search.sh:62
Finding

Automatic Installation of an Unpinned Runtime Dependency

Content
View full analysis
/dev/null; then warn "requests module not found. Attempting to install..." pip3 install requests --user fi ``` ### Technical Analysis The wrapper automatically invokes `pip3 install requests --user` when the dependency is absent. The package version is not pinned, hashes are not verified, an isolated environment is not used, and the user is not asked to approve the installation. The package source is determined by the user's active pip configuration and environment. This can include a custom index, mirror, proxy, or configuration supplied through variables such as `PIP_INDEX_URL`. Therefore, the code trusts mutable external package metadata and content at Skill runtime. A malicious source distribution can execute build-backend code during installation. A malicious installed module can also execute when the Python script subsequently imports `requests`. Although the package name is legitimate and the audit found no evidence that its current upstream release is malicious, the installation method creates an avoidable supply-chain exposure. ### Attack Path 1. The `requests` module is unavailable in the selected Python environment. 2. An attacker compromises or controls the configured pip index, mirror, DNS/proxy path, pip configuration, or relevant environment settings. 3. The user launches `scripts/run_search.sh`. 4. The wrapper automatically runs `pip3 install requests --user`. 5. Pip retrieves and installs attacker-controlled package content or a compromised dependency release. 6. Malicious build code executes during installation, or malicious module code executes when `twitter_search.py` imports `requests`. ### Impact Assessment Exploitation can result in arbitrary code execution under ...[truncated 440 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/run_search.sh:130
Finding

API Credential Exposure Through Process Arguments, Shell History, and Diagnostic Output

Content
View full analysis
&2 echo "Query: $QUERY" >&2 echo "Max Results: $MAX_RESULTS" >&2 echo "Query Type: $QUERY_TYPE" >&2 echo "API Key: $API_KEY_MASK" >&2 echo "---" >&2 # Run the Python script python3 "$SCRIPT_DIR/twitter_search.py" "$TWITTER_API_KEY" "$QUERY" \ --max-results "$MAX_RESULTS" \ --query-type "$QUERY_TYPE" \ --format "$FORMAT" ``` The documentation also encourages placing credentials directly on the command line: ```bash ./scripts/run_search.sh "AI" --api-key YOUR_KEY scripts/twitter_search.py "$API_KEY" "AI" ``` ### Technical Analysis Command-line arguments are inappropriate for secret transmission. The complete API key can be recorded in shell history when supplied through `--api-key`. Regardless of its original source, the wrapper then places the complete key in the Python process argument vector. Depending on operating-system process visibility, account boundaries, container configuration, monitoring agents, audit tools, and diagnostic collection, process arguments may be observable through process-listing interfaces or captured in logs. The wrapper additionally emits the first eight characters of the key to standard error. Although this is only a partial disclosure, it is unnecessary and may aid credential correlation or identification. The actual network use in `scripts/twitter_search.py:90-102` is consistent with the declared functionality: the key is sent as an `X-A ...[truncated 1854 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (16)

Tainted flow: 'headers' from os.environ.get (line 92, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/twitter_search.py (reported line 104)May include surrounding context.

python
}

    try:
        response = requests.get(API_BASE_URL, headers=headers, params=params, timeout=30)
        response.raise_for_status()
        return response.json()
    except requests.exceptions.RequestException as e:

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

00 relevant tweets, and analyze the data to produce professional reports with insights, statistics, and actionable recommendations.

Prerequisites

API Key Required: Users must configure their Twitter API key from https://twitterapi.io

The API key can be provided in three ways:

  1. Environment variable (recommended): Set TWITTER_API_KEY in your ~/.bashrc or ~/.zshrc
    bash
    echo 'export TWITTER_API_KEY="your_key_here"' >> ~/.bashrc
    source ~/.bashrc
    
  2. As an argument: Use --api-key YOUR_KEY with the wrapper script
  3. Passed directly: As first argument to the Python script

Quick Start

Using the Wrapper Script (Recommended)

The wrapper script automatically handles environment variable loading and dependency checks:

bash
# Basic search (uses TWITTER_API_KEY from shell config)
./scripts/run_search.sh "AI"

# With custom API key
./scripts/run_search.sh "AI" --api-key YOUR_KEY

# With options
./scripts/run_search.sh "\"Claude AI\"" --ma

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/run_search.sh (reported line 51)May include surrounding context.

sh
ER_API_KEY" && -f "$HOME/.zshrc" ]]; then
        eval "$(grep -E '^export TWITTER_API_KEY=' "$HOME/.zshrc" 2>/dev/null || true)"
    fi

    # If still not set, show error
    if [[ -z "$TWITTER_API_KEY" ]]; then
        error_exit "TWITTER_API_KEY is not set. Please set it in your shell config or pass as --api-key argument.

Get your API key from: https://twitterapi.io

To set it permanently:
  echo 'export TWITTER_API_KEY=\"your_key_here\"' >> ~/.bashrc
  source ~/.bashrc"
    fi

    warn "TWITTER_API_KEY loaded from shell config file"
fi

# Check Python is available
if ! command -v python3 &> /dev/null; then
    error_exit "python3 is not installed. Please install Python 3."
fi

# Check if requests module is available
if ! python3 -c "import requests" 2>/dev/null; then
    warn "requests module not found. Attempting to install..."
    pip3 install requests --user
fi

# Default values
MAX_RESULTS=${MAX_RESULTS:-1000}
QUERY_TYPE=${QUERY_TYPE:-Top}
FORMAT=${FORMAT:-json}

# Parse com

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/twitter_search.py (reported line 57)May include surrounding context.

python
def get_api_key(api_key_arg: Optional[str]) -> str:
    """
    Get API key from argument or environment variable.

    Args:
        api_key_arg: API key passed as argument

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill documents use of environment variables and network access, but it does not declare an explicit tool scope such as permissions or allowed-tools. That mismatch can cause the agent platform to invoke the skill without clear guardrails, increasing the chance of unintended secret access or outbound requests beyond what the user expects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description is broad enough to match many generic social-media or analysis requests, which raises the risk of over-triggering the skill in situations where users did not intend external Twitter/API access. In agent environments, overbroad routing can lead to unnecessary data transmission and unexpected use of credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill encourages fetching up to 1000 tweets and even using web search for context, but it does not explicitly warn that user-provided topics, handles, or related data will be sent to external services. This creates a privacy and compliance risk, especially if users enter sensitive investigations, internal project names, or personal identifiers.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow and examples bias searches toward English-language tweets without making language filtering an explicit user choice. This is less a security flaw than a product-safety and fairness issue, because it can silently exclude relevant non-English content and mislead downstream analysis.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script reads shell startup files and evals extracted content to obtain TWITTER_API_KEY, giving the skill unnecessary access to local shell configuration and causing execution of content derived from dotfiles. Even though it filters for export TWITTER_API_KEY=, using eval on attacker-modifiable dotfiles can trigger command substitution or other shell side effects, making this a real code-execution and secret-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script evaluates content sourced from .bashrc/.zshrc without a prominent user-facing warning or consent, which is dangerous because shell rc files are executable content, not trusted data stores. In the skill context, a Twitter search wrapper has no strong justification to execute anything from local shell initialization files, so this materially increases risk relative to the stated purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The wrapper installs Python packages at runtime with pip3 install requests --user, which expands the skill's capabilities beyond Twitter search into modifying the local environment and executing package-install logic from external repositories. In an agent or automated execution context, this creates supply-chain and environment-integrity risk, especially if package indexes, dependency resolution, or user site-packages are untrusted or manipulated.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/twitter_api.md (reported line 7)May include surrounding context.

md
# Constants
API_BASE_URL = "https://api.twitterapi.io/twitter/tweet/advanced_search"
DEFAULT_MAX_RESULTS = 1000
RESULTS_PER_PAGE = 20

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/twitter_search.py (reported line 45)May include surrounding context.

python
# Constants
API_BASE_URL = "https://api.twitterapi.io/twitter/tweet/advanced_search"
DEFAULT_MAX_RESULTS = 1000
RESULTS_PER_PAGE = 20

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script transmits both the user's search query and the API credential to a third-party service, but it provides no explicit consent, warning, or privacy notice at the point of use. In an agent-skill context, users may not realize their prompts or searched terms could contain sensitive information that will be disclosed externally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

Multiple canned queries default to lang:en without telling the user that language scoping is optional. In context, this can skew results and produce incomplete analysis while appearing authoritative.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file explains use of an external API with an X-API-Key credential and later documents retrieval of tweet text, user profiles, locations, and engagement metadata, but it does not include any user-facing warning about credential sensitivity or data/privacy impact. Under the markdown-specific missing-warning rule, externally transmitted queries and collected social-media data should be accompanied by a disclosure when the description could affect privacy or account security.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.