T09 · Insecure Skill Coding Practices
- Location
scripts/x_analyzer.py:1- Finding
Silent Substitution of Fabricated X Post Data After Retrieval Failure
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly an X/Twitter analysis helper, but it asks agents to activate silently, fetch external data, and spawn subagents without clear user control.
Review this before installing if you do not want a skill to silently fetch X/web content or launch subagents during analysis. It does not show credential theft, persistence, or destructive behavior, but its activation and deep-dive behavior should be made more explicit and user-controlled.
scripts/x_analyzer.py:1Silent Substitution of Fabricated X Post Data After Retrieval Failure
The skill documents shell-like command execution paths (xurl ...) and references script resources, but it does not declare an explicit tool scope such as allowed tools or permissions. That mismatch can cause the runtime to grant broader-than-intended capabilities or make review of actual execution privileges difficult, increasing the chance of unintended external access or command execution during activation.
The description contains broad triggers such as mentions of X/Twitter URLs, requests to analyze or summarize, engagement checks, trends, replies, and 'project-like structure breakdowns,' which can match many ordinary user requests. Overbroad activation increases the likelihood that the skill runs in unintended contexts, potentially pulling external content, invoking tools, or shaping responses when the user did not specifically request this capability.
The quick-start guidance says to trigger on broad phrases like 'analyze thread,' 'X trends,' and 'post engagement' without defining exclusion criteria or confirmation steps. In a skill that can fetch remote data and chain to subagents, underspecified activation logic is risky because it can silently expand scope, perform unnecessary external retrieval, or launch deeper analysis in contexts only loosely related to X.
This Python code executes an external command via subprocess.run in fetch_xurl, but the file provides no docstring, comment, logging, or prompt disclosing that it will invoke the xurl CLI on the user's system. Because subprocess execution is a safety-relevant operation under this rule, the absence of any visible warning or explanation makes the behavior insufficiently disclosed.
No suspicious patterns detected.