Back to skill

Security audit

X 帖子全链路调研:搜索、帖子详情与回复分析【Gecho 官方】

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed X/Twitter research workflow that routes user-requested searches and post lookups through Gecho's MCP tools without instructing account mutations.

Before installing, understand that this skill only becomes functional after you configure Gecho Bridge, install the Gecho Chrome extension, and keep Chrome logged into both Gecho and X. Use it only if you are comfortable letting the bridge read X content available in your logged-in browser session and optionally save returned search/post data as local JSON files.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The manifest description and the full skill instructions are presented only in Chinese, which effectively forces a specific language on users. The file does not offer multilingual options, ask for user language preference, or explain that the skill is intentionally limited to a Chinese-speaking audience or region.

Static analysis

No suspicious patterns detected.