Back to skill

Security audit

Grok X Analyzer

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly an X/Twitter analysis helper, but it asks agents to activate silently, fetch external data, and spawn subagents without clear user control.

Review this before installing if you do not want a skill to silently fetch X/web content or launch subagents during analysis. It does not show credential theft, persistence, or destructive behavior, but its activation and deep-dive behavior should be made more explicit and user-controlled.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/x_analyzer.py:1
Finding

Silent Substitution of Fabricated X Post Data After Retrieval Failure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documents shell-like command execution paths (xurl ...) and references script resources, but it does not declare an explicit tool scope such as allowed tools or permissions. That mismatch can cause the runtime to grant broader-than-intended capabilities or make review of actual execution privileges difficult, increasing the chance of unintended external access or command execution during activation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description contains broad triggers such as mentions of X/Twitter URLs, requests to analyze or summarize, engagement checks, trends, replies, and 'project-like structure breakdowns,' which can match many ordinary user requests. Overbroad activation increases the likelihood that the skill runs in unintended contexts, potentially pulling external content, invoking tools, or shaping responses when the user did not specifically request this capability.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The quick-start guidance says to trigger on broad phrases like 'analyze thread,' 'X trends,' and 'post engagement' without defining exclusion criteria or confirmation steps. In a skill that can fetch remote data and chain to subagents, underspecified activation logic is risky because it can silently expand scope, perform unnecessary external retrieval, or launch deeper analysis in contexts only loosely related to X.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

This Python code executes an external command via subprocess.run in fetch_xurl, but the file provides no docstring, comment, logging, or prompt disclosing that it will invoke the xurl CLI on the user's system. Because subprocess execution is a safety-relevant operation under this rule, the absence of any visible warning or explanation makes the behavior insufficiently disclosed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.