Back to skill

Security audit

Twitter/X Reader

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says: it reads public X/Twitter posts by contacting documented third-party tweet services, with no persistence or credential use found.

Install only if you are comfortable sending the tweet author and status ID you ask about to FxTwitter, and possibly Nitter fallback instances. Avoid passing arbitrary user-controlled max_depth values to the thread script until it validates a bounded integer.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/read_thread.sh:19
Finding

Command Injection Through Unvalidated Thread Depth Argument

Content
View full analysis
Remediation
View remediation
50 )); then echo '{"error":"max_depth must be a decimal integer from 1 to 50"}' | jq . exit 1 fi ``` The `10#` prefix forces base-10 interpretation after the regular-expression check, avoiding unexpected octal handling for values with leading zeroes. Additional hardening measures: 1. Keep a fixed upper bound to prevent excessive network requests and resource consumption. 2. Do not pass natural-language or otherwise untrusted values directly as the second argument. 3. Add regression tests that reject letters, signs, whitespace, shell metacharacters, arithmetic expressions, array syntax, and command-substitution syntax. 4. Run the Skill under a minimally privileged account with limited filesystem and credential access. 5. Consider removing the configurable depth argument entirely if a fixed limit is sufficient for the declared functionality. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger conditions are broad enough that the skill may auto-activate on generic requests such as 'read this tweet' or mentions of getting information from a tweet, which can cause unnecessary network access to third-party services without sufficiently explicit user intent. In an agent environment, overly permissive invocation increases the chance of accidental data handling and external requests beyond what the user clearly requested.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The skill transmits user-supplied tweet URLs and derived identifiers to external third-party services such as api.fxtwitter.com and potentially public Nitter instances. Even though the target content is public, this creates a real external data transmission path and exposes user activity, request metadata, and possibly sensitive contextual interest patterns to non-first-party services.

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
## Technical Implementation

### Primary Method: FxTwitter API
- **Endpoint:** `https://api.fxtwitter.com/{username}/status/{tweet_id}`
- **Advantages:** No authentication, comprehensive data, reliable
- **Rate Limits:** Generous for personal use
- **Response:** Complete JSON with all tweet metadata

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/read_thread.sh (reported line 34)May include surrounding context.

sh
fetch_tweet() {
    local user="$1"
    local tweet_id="$2"
    curl -s -A "OpenClaw-TwitterReader/1.0" "https://api.fxtwitter.com/$user/status/$tweet_id"
}

# Extract media from tweet data (comprehensive)

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The hardcoded request to https://api.fxtwitter.com causes user-requested tweet identifiers to be transmitted to an external service. In the context of an agent skill, this creates a privacy and data-governance risk because operator and user expectations may be that the tool only parses a URL locally rather than contacting an unaffiliated third party.

Content

Scanner excerpt · scripts/read_tweet.sh (reported line 62)May include surrounding context.

sh
tweet_id=$(echo "$tweet_info" | cut -d' ' -f2)

# Build FxTwitter API URL
api_url="https://api.fxtwitter.com/$user/status/$tweet_id"

# Make API request
if ! response=$(curl -s -A "OpenClaw-TwitterReader/1.0" "$api_url"); then

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script takes a user-supplied tweet URL, extracts the username and tweet ID, and sends that metadata to the third-party service api.fxtwitter.com. This is an external data transmission to a non-Twitter endpoint without any runtime disclosure, consent, or trust boundary warning, which can expose user activity and queried content to that service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The feature list proposes 'Translation support for non-English tweets' without indicating that language changes should be user-selected. This can conflict with language or locale policy if the skill later translates content automatically instead of preserving the user's preferred language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.