Back to skill

Security audit

Grok X Growth Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is openly designed to run an autonomous X affiliate-promotion agent, but it gives broad posting and credential use with weak user controls and under-disclosed risks.

Treat this as a high-risk Review item before installing. Use only with explicit human approval for posts, clear affiliate and automation disclosure, a pinned and verified ThumbGate version, isolated setup, least-privilege X credentials, secure secret storage, and a clear privacy policy for any X content sent to xAI.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
setup-guide.md:3
Finding

Unpinned Third-Party Package Is Downloaded and Executed via npx

Content
View full analysis

Vulnerability Details

File Location: setup-guide.md, line 3
Vulnerability Type: Supply-chain risk from unpinned dependency execution
Risk Level: Medium

Vulnerable Code

markdown
1. Install ThumbGate: `npx thumbgate init --agent openclaw`

Technical Analysis

The setup guide directs users to execute the thumbgate package through npx without specifying an exact version. Depending on the local npm configuration and cache state, npx can retrieve the package from the configured registry and immediately execute its package entry point.

The project does not provide a version pin, lockfile, integrity hash, verified publisher information, or vendored and auditable copy of the dependency. Consequently, the code executed during installation may differ from the code reviewed when this skill was published. A compromised package release, registry account, dependency tree, or registry configuration could result in arbitrary local code execution.

This finding concerns the unsafe dependency-loading mechanism. The reviewed files do not establish that the current thumbgate package is malicious.

Attack Path

  1. An attacker compromises the package, its publisher account, a transitive dependency, or the package source selected by the user's npm configuration.
  2. The attacker publishes or serves a malicious package version under the expected package name.
  3. A user follows the setup guide and runs:
    bash
    npx thumbgate init --agent openclaw
    
  4. npx resolves and downloads the uncontrolled package version.
  5. The package's initialization code executes with the privileges of the invoking user.
  6. The malicious code can access resources available to that user and alter the local OpenClaw setup. If credentials have already been configured or are otherwise present in the environment, they may also be exposed.

Impact Assessment

Successful exploitation permits arbitrary code execution with the invoking user's privileges. Th ...[truncated 687 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin ThumbGate to an exact, reviewed version rather than allowing dynamic resolution:
    bash
    npx --yes thumbgate@X.Y.Z init --agent openclaw
    
  2. Publish a lockfile or equivalent dependency manifest with integrity metadata.
  3. Document the expected registry, package publisher, repository, release signature, and package checksum.
  4. Verify package provenance and integrity before execution, using npm provenance attestations or cryptographic signatures where available.
  5. Audit the pinned package and its transitive dependency tree before recommending it.
  6. Run initialization in an isolated, least-privileged environment without production credentials.
  7. Configure X and xAI credentials only after installation and verification have completed.
  8. Prefer a locally installed, pinned dependency invoked with network installation disabled for subsequent runs.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The text advertises automated affiliate-link replies delivered in a 'witty, human-like tone' and framed to avoid spam detection, which is deceptive automation intended to impersonate authentic human participation. This is dangerous because it facilitates stealth advertising, platform-policy evasion, and manipulation of real users who are not informed they are engaging with an autonomous promoter.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly describes autonomous monitoring of X and automatic posting of affiliate-link replies, but it does not warn users about the platform, compliance, and reputational risks of unattended promotional posting. In this context, the omission is dangerous because the skill is designed to engage in behavior that can resemble spam or undisclosed advertising, and the 'ThumbGate' language focuses on evading penalties rather than informing the operator of the underlying risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill states it monitors X content and uses the xAI/Grok API to generate replies, which implies transmitting tweet content and possibly user-related context to a third-party model provider, yet it provides no privacy or data-handling warning. This is especially concerning because the agent operates continuously and at scale, increasing the likelihood of sending personal data, sensitive discussions, or regulated content to external services without operator awareness or appropriate safeguards.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The copy explicitly promotes continuous autonomous monitoring of a niche timeline and automated posting behavior ('read your niche's timeline 24/7' and 'drop your affiliate links naturally') without any defined user-initiated trigger, approval gate, or bounded scope. In the context of an agent skill, this enables persistent unsolicited engagement and makes abuse at scale much more likely, especially since the goal is monetization rather than user assistance.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Using npx thumbgate without a pinned version allows whatever package version is current at execution time to be fetched and run, creating a supply-chain risk. In this skill, the command is part of initial setup and is positioned before secrets are configured, so a malicious or compromised package could alter the environment, implant persistence, or capture credentials entered later.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide instructs users to place CLIENT_SECRET and XAI_API_KEY into the environment but provides no warning about secret storage, exposure, or least-privilege handling. Because this skill is designed for autonomous posting and monetization, those credentials are especially sensitive: compromise could enable account takeover, unauthorized API usage, spam activity, and abuse of affiliated accounts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.