Back to skill

Security audit

Tweet Summarizer Lite

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it asks users to hand full Twitter/X session cookies to an unpinned third-party CLI and passes that CLI the entire process environment.

Install only if you are comfortable giving a third-party bird executable full Twitter/X session cookies and exposing any secrets in the agent's environment to that process. Use a dedicated low-risk Twitter/X account, avoid running with unrelated API keys in the environment, verify/pin the bird version yourself, and periodically delete stored tweets under the local OpenClaw data directory.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
scripts/tweet.py:23
Finding

Unpinned Third-Party CLI Receives Full-Account Session Cookies and the Complete Process Environment

Content
View full analysis

Vulnerability Details

File Location: scripts/tweet.py:23-39; supporting installation and credential instructions at README.md:28-38 and permission declarations at SKILL.md:5-10
Vulnerability Type: Unpinned dependency with excessive credential and environment exposure
Risk Level: High

Vulnerable Code

scripts/tweet.py:23-39:

python
auth_token = os.getenv('AUTH_TOKEN')
ct0 = os.getenv('CT0')

if not auth_token or not ct0:
    print("❌ Twitter credentials not set")
    print("   Set AUTH_TOKEN and CT0 environment variables")
    print("   See SECURITY.md for how to obtain these safely")
    return None

try:
    result = subprocess.run(
        ['bird', 'read', url_or_id, '--plain'],
        env={**os.environ, 'AUTH_TOKEN': auth_token, 'CT0': ct0},
        capture_output=True,
        text=True,
        timeout=10
    )

README.md:28-38:

markdown
Requires the [`bird`](https://github.com/steipete/bird) CLI and valid Twitter session cookies.

```bash
npm install -g @steipete/bird

Set your credentials (see SECURITY.md for how to get these):

bash
export AUTH_TOKEN="your_auth_token"
export CT0="your_ct0_token"
text

`SKILL.md:5-10`:

```yaml
requiredEnv:
  - AUTH_TOKEN
  - CT0
requiredBins:
  - bird
permissions:
  - network: Contact X/Twitter API via bird CLI (uses session cookies)

Technical Analysis

Fetching a tweet requires authenticated network access, so providing Twitter credentials to a trusted client is consistent with the declared functionality. However, the implementation delegates credential handling to a globally installed third-party CLI without pinning or verifying its version or integrity.

The command npm install -g @steipete/bird resolves the package version at installation time. Consequently, the effective executable can change after this Skill has been audited. If the upstream ...[truncated 2802 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin and verify the dependency

    • Require a specific reviewed bird version rather than installing the latest available release.
    • Use a project-local dependency instead of an unrestricted global installation where possible.
    • Verify package integrity using a lockfile, registry integrity metadata, checksums, or signed releases.
    • Document the exact supported version and establish a controlled process for reviewing upgrades.
  2. Pass a minimal subprocess environment

    • Do not spread os.environ into the child process.
    • Construct an allowlisted environment containing only the values strictly required by the CLI, such as AUTH_TOKEN, CT0, and narrowly selected runtime variables required for execution.
    • Resolve the expected executable to a trusted absolute path before invocation rather than relying solely on executable search-path resolution.
  3. Reduce credential privilege

    • Prefer an official, read-only, narrowly scoped API credential if the service supports one.
    • If session cookies remain necessary, use a dedicated account with minimal access and no posting or administrative significance.
    • Rotate the cookies regularly and immediately after any suspected dependency compromise.
  4. Constrain execution and network access

    • Run the external CLI in a sandbox with access only to the minimum required files and network destinations.
    • Restrict outbound traffic to documented Twitter/X endpoints where the runtime supports network allowlisting.
    • Prevent the subprocess from accessing unrelated credential stores, agent state, and workspace files.
  5. Improve operational controls

    • Audit the selected dependency version before distribution.
    • Monitor account activity and outbound requests for unexpected behavior.
    • Clearly disclose that a third-party executable receives full session cookies and explain the associated supply-chain risk.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (17)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 31)May include surrounding context.

text
*.egg

# Virtual environments
.env
.venv
env/
venv/

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY.md (reported line 33)May include surrounding context.

export AUTH_TOKEN="your_token_here" export CT0="your_ct0_here"

Or use a .env file (NOT committed to git)

and load with: source .env

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY.md (reported line 34)May include surrounding context.

export AUTH_TOKEN="your_token_here" export CT0="your_ct0_here"

Or use a .env file (NOT committed to git)

and load with: source .env

text

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

The code forwards the entire parent environment to an external CLI process using {**os.environ, ...}, which can expose unrelated secrets to a third-party tool unnecessarily. In an agent skill setting this is more dangerous because the skill may run in environments containing API keys, tokens, or internal configuration not needed for fetching a tweet, expanding the blast radius if the external binary is compromised, misbehaves, or logs its environment.

Content

Scanner excerpt · scripts/tweet.py (reported line 35)May include surrounding context.

python
try:
        result = subprocess.run(
            ['bird', 'read', url_or_id, '--plain'],
            env={**os.environ, 'AUTH_TOKEN': auth_token, 'CT0': ct0},
            capture_output=True,
            text=True,
            timeout=10

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advertises broad natural-language triggers like "What does this tweet say?" and says "no commands needed," which can cause the agent to invoke the skill in situations broader than a user may expect. In an agent ecosystem, ambiguous activation increases the chance of unintended tweet fetching, storage, or summarization from pasted links or casual conversation, especially when the skill also performs persistence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README instructs users to export Twitter session cookies and save fetched tweets locally, but it does not prominently warn that these tokens are sensitive credentials or explain the privacy/security implications of storing tweet content on disk. In practice, this can lead users to expose reusable session material in shell history or logs and to retain collected data in a predictable local path without informed consent or safeguards.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The skill explicitly persists fetched tweet data to a user-local workspace directory, creating session persistence and data retention risk. Even if intended for later search, saved content can expose user interests, queried URLs, or sensitive tweet contents to other local processes, future sessions, or anyone with filesystem access, especially when retention limits and deletion behavior are not defined.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
- bird
permissions:
  - network: Contact X/Twitter API via bird CLI (uses session cookies)
  - filesystem: Write tweets to ~/.openclaw/workspace/data/tweets/
---

# Tweet Summarizer Lite

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill metadata and usage text disclose that tweets are written to local storage in permissions, but the user-facing guidance does not clearly warn that fetching a tweet will persist content under the workspace. This can create an informed-consent and privacy issue because users may believe they are performing a transient lookup when the skill actually stores third-party content and potentially sensitive browsing targets locally.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The helper goes beyond checking whether credentials are present and actively instructs the user to extract live Twitter session cookies from browser developer tools. Session cookies such as auth_token and ct0 are sensitive authentication artifacts; encouraging manual extraction increases the chance of account compromise, policy violations, and unsafe handling of credentials outside the browser.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

These lines explicitly direct users to retrieve Twitter session cookie values from their browser and export them into the shell environment. That practice normalizes credential exfiltration from a user session into less protected contexts, where tokens may be exposed through shell history, process environments, logs, or accidental reuse, and it may also circumvent platform terms or intended access controls.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description says the script fetches and optionally summarizes a tweet, but the code also persistently stores tweet contents under the user's home directory. In an agent skill context, undocumented persistence is security-relevant because it can retain potentially sensitive or unexpected data without clear user consent or operator awareness.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/tweet.py (reported line 33)May include surrounding context.

python
return None
    
    try:
        result = subprocess.run(
            ['bird', 'read', url_or_id, '--plain'],
            env={**os.environ, 'AUTH_TOKEN': auth_token, 'CT0': ct0},
            capture_output=True,

Tainted flow: 'auth_token' from os.getenv (line 23, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/tweet.py (reported line 33)May include surrounding context.

python
return None
    
    try:
        result = subprocess.run(
            ['bird', 'read', url_or_id, '--plain'],
            env={**os.environ, 'AUTH_TOKEN': auth_token, 'CT0': ct0},
            capture_output=True,

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/tweet.py (reported line 87)May include surrounding context.

python
tweets[tweet_id] = {
        'text': tweet_text,
        'timestamp': str(__import__('datetime').datetime.now().isoformat())
    }
    
    with open(tweet_file, 'w') as f:

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
75% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · SECURITY.md (reported line 7)May include surrounding context.

md
## ⚠️ Cookie Authentication

This skill uses the `bird` CLI which requires Twitter session cookies (`AUTH_TOKEN` and `CT0`). These are **sensitive credentials** that grant full access to your Twitter account.

### Risks

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The line instructs the agent to 'Respond naturally, then exec the appropriate script,' while also mandating a specific execution style ('the user never types python3') rather than offering user choice. This is a natural-language constraint on interaction behavior that may override user preferences without explicit opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This manifest file says the skill can 'Fetch and summarize single tweets from Twitter/X - Lite version,' but it does not specify concrete trigger phrases, invocation boundaries, or exclusion conditions. In manifest files, broad capability descriptions without explicit scope can lead to ambiguous activation and unintended invocation overlap with other social-media or summarization tasks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.