Back to skill

Security audit

Twitter/X scraper with Apify actors

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to do what it says: run Apify-based Twitter/X follower collection with optional email enrichment, but users should handle privacy and API-token risks carefully.

Install only if you are authorized to collect and enrich this Twitter/X audience data. Prefer APIFY_TOKEN from a managed secret store instead of --apify-token, use a narrowly scoped/revocable Apify token, keep --include-emails off unless there is a lawful and policy-compliant reason, and pin dependencies/install sources for production use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/apify_twitter_actors.py:65
Finding

Apify API Token Transmitted in a URL Query Parameter

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/apify_twitter_actors.py:257
Finding

API Token Accepted and Documented as a Command-Line Argument

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unpinned Python and Installation Dependencies Reduce Supply-Chain Reproducibility

Content
View full analysis
=2.31.0 ``` The documented installation process resolves dependencies dynamically: ```bash pip install -r requirements.txt ``` The README also documents an `npx`-based installation command without an immutable package or repository revision: ```bash npx skills add hundevmode/twitter-x-apify-actors-openclaw-skill --skill twitter-x-apify-actors ``` ```bash npx skills add hundevmode/twitter-x-apify-actors-openclaw-skill --list ``` ### Technical Analysis A lower-bound-only Python requirement does not produce reproducible installations. A future `requests` release may be selected without having been reviewed with this Skill. Similarly, the documented `npx` workflow does not identify an immutable version of the invoked installer or an immutable revision of the Skill source. No malicious dependency, typosquatted name, or currently compromised package was identified in the reviewed files. The vulnerability is the absence of version and integrity controls, which increases exposure to future upstream compromise, unexpected behavior changes, or incompatible releases. ### Attack Path 1. An upstream dependency, installer release, or mutable repository revision is compromised or publishes an unsafe update. 2. A user later follows the documented `pip install` or `npx` installation workflow. 3. The package manager resolves the then-current allowed version rather than a previously audited immutable version. 4. Installation hooks or imported package code execute in the user's environment. 5. The compromised component gains the permissions of the installing or running user. This path is conditional on an upstream compromise or unsafe future release; ...[truncated 602 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Tainted flow: 'params' from os.getenv (line 66, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/apify_twitter_actors.py (reported line 67)May include surrounding context.

python
url = f"{APIFY_BASE}/{actor_id}/run-sync-get-dataset-items"
    params = {"token": token, "format": "json", "clean": "true"}
    resp = requests.post(url, params=params, json=payload, timeout=timeout_sec)

    if resp.status_code >= 400:
        raise SkillError(f"Actor {actor_id} failed: HTTP {resp.status_code} - {resp.text[:500]}")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README promotes optional email enrichment and outreach-ready lead export but does not warn users that this workflow processes potentially sensitive personal data and may trigger privacy, consent, platform-policy, or regulatory obligations. In this skill context, the omission is more concerning because the stated purpose is lead generation and outbound automation, increasing the chance of misuse or non-compliant data handling at scale.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documents use of environment variables and external network access to Apify actors, but it does not declare any explicit tool scope such as allowed tools or permissions. That creates an authorization and review gap: operators and automated policy systems cannot easily constrain or audit what the skill is permitted to access, increasing the chance of unintended network calls or secret exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly supports collecting followers/following data and enriching usernames with email addresses, which is privacy-sensitive processing of personal data. Without any warning, consent guidance, or use restrictions, users may employ the workflow in ways that violate privacy expectations, platform rules, or internal compliance requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation tells users to pass the Apify API token as a command-line argument, which can leak secrets through shell history, process listings, CI logs, or telemetry. Since this token authorizes access to Apify resources, exposure could allow unauthorized actor execution, data access, or account abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly supports collecting Twitter/X followers and then enriching those usernames into email addresses, but the contract provides no privacy, consent, rate-limit, or acceptable-use warning. That creates a real privacy and abuse risk because it operationalizes mass contact discovery for people derived from a target account's social graph, which can enable scraping, profiling, spam, or phishing at scale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The troubleshooting example includes --include-emails in a minimal smoke test without any accompanying warning that email enrichment may collect or process sensitive personal data. In a skill explicitly designed for Twitter/X audience collection and enrichment, normalizing email collection as the default test path increases the chance that users will perform unnecessary PII enrichment, creating privacy, compliance, and data-handling risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/apify_twitter_actors.py (reported line 22)May include surrounding context.

python
FOLLOWER_ACTOR_DEFAULT = "bIYXeMcKISYGnHhBG"
EMAIL_ACTOR_DEFAULT = "mSaHt2tt3Z7Fcwf0o"
APIFY_BASE = "https://api.apify.com/v2/acts"


class SkillError(Exception):

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The script transmits user-supplied targets, collected usernames, and optionally enrichment inputs to an external service, which is an intentional capability of this skill. In context this is expected, but it is still security-relevant because it moves potentially sensitive collected data off-host to a third party, and the token is included in request parameters rather than a header.

Content

Scanner excerpt · scripts/apify_twitter_actors.py (reported line 67)May include surrounding context.

python
url = f"{APIFY_BASE}/{actor_id}/run-sync-get-dataset-items"
    params = {"token": token, "format": "json", "clean": "true"}
    resp = requests.post(url, params=params, json=payload, timeout=timeout_sec)

    if resp.status_code >= 400:
        raise SkillError(f"Actor {actor_id} failed: HTTP {resp.status_code} - {resp.text[:500]}")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

When --include-emails is used, the script forwards collected usernames to a second external Apify actor for enrichment without any explicit consent prompt or prominent disclosure at the point of use. In a data-collection skill, this matters because users may assume processing stays within the first actor/workflow, while the second transmission expands third-party sharing and privacy/compliance risk.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency is specified as requests>=2.31.0, which allows installation of any newer release without guaranteeing reproducibility or review. This can introduce supply-chain risk and make builds silently pick up vulnerable or breaking versions over time, especially important in a skill that may interact with external APIs and process user-supplied URLs or handles.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The manifest includes requests without pinning an exact version, while the package has multiple known advisories across versions. Because the installed version is unconstrained beyond a minimum, it is not possible to verify from this file alone whether deployments will avoid affected releases, which is risky for a skill likely to make outbound HTTP requests and potentially handle attacker-controlled links or remote endpoints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The code reads a sensitive API token from the APIFY_TOKEN environment variable to authenticate outbound requests. Under the code-file warning criteria, credential access should have some visible disclosure, comment, or documentation, and this file does not explain that environment credentials will be consumed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.