T08 · Insecure Dependencies
- Location
scripts/tweet.py:23- Finding
Unpinned Third-Party CLI Receives Full-Account Session Cookies and the Complete Process Environment
- Content
View full analysis
Vulnerability Details
File Location:
scripts/tweet.py:23-39; supporting installation and credential instructions atREADME.md:28-38and permission declarations atSKILL.md:5-10
Vulnerability Type: Unpinned dependency with excessive credential and environment exposure
Risk Level: HighVulnerable Code
scripts/tweet.py:23-39:python auth_token = os.getenv('AUTH_TOKEN') ct0 = os.getenv('CT0') if not auth_token or not ct0: print("❌ Twitter credentials not set") print(" Set AUTH_TOKEN and CT0 environment variables") print(" See SECURITY.md for how to obtain these safely") return None try: result = subprocess.run( ['bird', 'read', url_or_id, '--plain'], env={**os.environ, 'AUTH_TOKEN': auth_token, 'CT0': ct0}, capture_output=True, text=True, timeout=10 )README.md:28-38:markdown Requires the [`bird`](https://github.com/steipete/bird) CLI and valid Twitter session cookies. ```bash npm install -g @steipete/birdSet your credentials (see SECURITY.md for how to get these):
bash export AUTH_TOKEN="your_auth_token" export CT0="your_ct0_token"text `SKILL.md:5-10`: ```yaml requiredEnv: - AUTH_TOKEN - CT0 requiredBins: - bird permissions: - network: Contact X/Twitter API via bird CLI (uses session cookies)Technical Analysis
Fetching a tweet requires authenticated network access, so providing Twitter credentials to a trusted client is consistent with the declared functionality. However, the implementation delegates credential handling to a globally installed third-party CLI without pinning or verifying its version or integrity.
The command
npm install -g @steipete/birdresolves the package version at installation time. Consequently, the effective executable can change after this Skill has been audited. If the upstream ...[truncated 2802 chars]- Remediation
View remediation
Remediation Suggestions
-
Pin and verify the dependency
- Require a specific reviewed
birdversion rather than installing the latest available release. - Use a project-local dependency instead of an unrestricted global installation where possible.
- Verify package integrity using a lockfile, registry integrity metadata, checksums, or signed releases.
- Document the exact supported version and establish a controlled process for reviewing upgrades.
- Require a specific reviewed
-
Pass a minimal subprocess environment
- Do not spread
os.environinto the child process. - Construct an allowlisted environment containing only the values strictly required by the CLI, such as
AUTH_TOKEN,CT0, and narrowly selected runtime variables required for execution. - Resolve the expected executable to a trusted absolute path before invocation rather than relying solely on executable search-path resolution.
- Do not spread
-
Reduce credential privilege
- Prefer an official, read-only, narrowly scoped API credential if the service supports one.
- If session cookies remain necessary, use a dedicated account with minimal access and no posting or administrative significance.
- Rotate the cookies regularly and immediately after any suspected dependency compromise.
-
Constrain execution and network access
- Run the external CLI in a sandbox with access only to the minimum required files and network destinations.
- Restrict outbound traffic to documented Twitter/X endpoints where the runtime supports network allowlisting.
- Prevent the subprocess from accessing unrelated credential stores, agent state, and workspace files.
-
Improve operational controls
- Audit the selected dependency version before distribution.
- Monitor account activity and outbound requests for unexpected behavior.
- Clearly disclose that a third-party executable receives full session cookies and explain the associated supply-chain risk.
-
