Back to skill

Security audit

gingiris-twitter-agent-ops

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Twitter/X operations SOP, but it enables automated live posting and credential-based account control without enough explicit human approval and secret-handling safeguards.

Install only if you are comfortable giving an agent operational control over Twitter/X workflows. Keep API tokens in a proper secret store, do not paste credentials into MASTER-STATUS.md, require human approval before every live post, and review the included internal reference file before using the package.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list contains broad phrases like 'Buffer API', '素材库', and 'twitter automation' that can match generic user requests unrelated to this specific SOP. Over-broad activation can cause the skill to inject operational instructions, file-writing behavior, or posting guidance in contexts where the user did not intend to invoke this high-impact automation workflow.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The when-to-use section is expansive and does not clearly distinguish advisory use from execution-oriented use. In practice, this increases the chance that the agent will activate on general social-media questions and proceed into credential handling, persistent logging, or file modification behaviors without sufficiently explicit user intent.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill mandates reading and writing MASTER-STATUS.md every session but does not clearly warn users that the agent will modify local files as part of normal operation. Silent file mutation is risky because it creates persistent state changes that may surprise users, corrupt workflows, or be abused if the skill is auto-invoked.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill discusses credential separation and external posting through OAuth1 and Buffer API, yet it lacks a strong privacy/security notice about handling secrets and publishing to third-party platforms. Because this skill is designed for real account operations, accidental activation or unsafe storage of tokens could lead to unauthorized posting or credential exposure.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README explicitly promotes fully automated posting to a live Twitter/X account, but does not warn about risks such as accidental harmful posts, policy violations, account compromise blast radius, or the need for human review before publication. In this skill context, the danger is elevated because it is an operational SOP intended to be copied into agent workflows, making unsafe autonomous publication more likely in real deployments.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill instructs users to gather podcasts, interviews, conversations, and other first-hand materials into searchable transcripts without addressing consent, confidentiality, retention, or lawful processing. That can lead operators to ingest private or sensitive material into an agent knowledge base, increasing the risk of privacy violations, unauthorized disclosure, and downstream misuse in generated content.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README promotes fully automated Twitter/X account operation, posting, and tracking without explicit safeguards around account owner consent, platform policy compliance, credential handling, or privacy of collected analytics. In this skill context, that is materially risky because it encourages real-world account automation and behavioral data collection, which can lead to account suspension, unauthorized posting, or mishandling of personal/account data.

Ssd 3

Medium
Confidence
96% confidence
Finding
The MASTER-STATUS.md template instructs persistent storage of operational account data and includes credential-routing details in a shared status file. Storing or repeatedly exposing account identifiers, posting history, and especially credential metadata in a broadly accessible markdown file increases the risk of secret leakage, lateral misuse, and unauthorized account operations.

Ssd 3

Medium
Confidence
94% confidence
Finding
The embedded system prompt directs the agent to persistently rely on retained account state across conversations and explicitly includes credential-routing instructions. This creates a dangerous pattern where sensitive operational context is treated as durable memory, increasing the likelihood of cross-session data leakage, unintended reuse, or unsafe autonomous actions such as posting to the wrong account.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.