Back to skill

Security audit

X Research by Gecho

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, read-only X research workflow, with the main caution that saved post and reply JSON may contain personal data.

Install only if you are comfortable connecting an AI workflow to your logged-in Chrome/X session through the Gecho extension. Save results only in trusted directories, assume raw JSON may contain personal data from posts, authors, and replies, and delete files you no longer need.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly supports saving raw X post and reply data to local JSON files, but it does not warn about privacy, retention, or handling of potentially sensitive social-media content. This can lead users to persist personal data, replies, and account-related context on disk without understanding the exposure or compliance implications.

Static analysis

No suspicious patterns detected.