Back to skill

Security audit

X Post Details by Gecho

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed workflow for collecting one X post and replies through Gecho Bridge, with no artifact-backed evidence of hidden or destructive behavior.

Install only if you are comfortable connecting Gecho Bridge and its Chrome extension to a logged-in X browser session. Review the Gecho Bridge package and extension source/trust before use, and provide a save directory only when you want collected post data written locally.

Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Content
Join the [WeCom group](https://github.com/gecho-ai/gecho-bridge/blob/main/qywx.jpg) or use the [1:1 support QR code](https://github.com/gecho-ai/gecho-bridge/blob/main/wx.jpg).

## Output guidelines

For success:
- Say the tool completed.
Confidence
85% confidence
Finding
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Static analysis

No suspicious patterns detected.