T09 · Insecure Skill Coding Practices
- Location
scripts/paste-from-clipboard.ts:35- Finding
AppleScript Injection Through the Unescaped Target Application Name
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly aligned with posting to X, but it needs review because it combines public posting automation with clipboard/keystroke control, broad process-kill recovery, and unpinned runtime execution.
Install only if you are comfortable granting an agent control over your real Chrome/X session, clipboard, file picker, and paste keystrokes. Review every post before publishing, avoid the --submit path unless you explicitly intend to publish, do not process untrusted Markdown with remote images, and prefer a preinstalled trusted Bun runtime instead of the npx fallback. Be especially cautious with the automatic Chrome process-kill troubleshooting instruction.
scripts/paste-from-clipboard.ts:35AppleScript Injection Through the Unescaped Target Application Name
scripts/x-utils.ts:257Automatic Execution of an Unpinned Bun Package Through npx
scripts/x-article.ts:76Predictable Shared Temporary File Allows Symlink-Based File Overwrite
scripts/md-to-html.ts:286Unrestricted Remote Markdown Image Resolution Creates an SSRF-Capable Workflow
The skill documents OS-level clipboard and keystroke automation, including frontmost-application interaction, which is more powerful than a simple social-posting abstraction suggests. Such automation can affect whatever window has focus and may interact with unrelated apps or sensitive content if context is wrong.
The skill documents OS-level clipboard and keystroke automation, including frontmost-application interaction, which is more powerful than a simple social-posting abstraction suggests. Such automation can affect whatever window has focus and may interact with unrelated apps or sensitive content if context is wrong.
The skill documents OS-level clipboard and keystroke automation, including frontmost-application interaction, which is more powerful than a simple social-posting abstraction suggests. Such automation can affect whatever window has focus and may interact with unrelated apps or sensitive content if context is wrong.
The skill documents OS-level clipboard and keystroke automation, including frontmost-application interaction, which is more powerful than a simple social-posting abstraction suggests. Such automation can affect whatever window has focus and may interact with unrelated apps or sensitive content if context is wrong.
The skill documents OS-level clipboard and keystroke automation, including frontmost-application interaction, which is more powerful than a simple social-posting abstraction suggests. Such automation can affect whatever window has focus and may interact with unrelated apps or sensitive content if context is wrong.
The skill documents OS-level clipboard and keystroke automation, including frontmost-application interaction, which is more powerful than a simple social-posting abstraction suggests. Such automation can affect whatever window has focus and may interact with unrelated apps or sensitive content if context is wrong.
The skill documents OS-level clipboard and keystroke automation, including frontmost-application interaction, which is more powerful than a simple social-posting abstraction suggests. Such automation can affect whatever window has focus and may interact with unrelated apps or sensitive content if context is wrong.
The skill documents OS-level clipboard and keystroke automation, including frontmost-application interaction, which is more powerful than a simple social-posting abstraction suggests. Such automation can affect whatever window has focus and may interact with unrelated apps or sensitive content if context is wrong.
Referenced artifact was not completely inspected
| `scripts/x-article.ts` | Long-form article publishing (Markdown), CDP fallback |
Referenced artifact was not completely inspected
| `scripts/x-article.ts` | Long-form article publishing (Markdown), CDP fallback |
Referenced artifact was not completely inspected
| `scripts/check-paste-permissions.ts` | Verify environment & permissions |
The skill explicitly instructs the agent to kill Chrome CDP instances and retry without user warning or approval. Silent destructive actions on local processes violate least surprise and can interrupt unrelated tasks, especially because the match pattern is broad and not limited to processes started by the skill.
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
n for 30 seconds for preview...');
await sleep(30_000);
}
} finally {
let leaveChromeOpen = false;
if (chrome && loggedInDuringRun && cdp && sessionId) {
console.log('[x-quote] Waiting for X session cookies to persist...');
const sessionReady = await waitForXSessionPersistence({ cdp, sessionId });
if (!sessionReady) {
console.warn('[x-quote] X session cookies not observed yet. Leaving Chrome open so login can finish persisting.');
leaveChromeOpen = true;
}
}
if (cdp) {
if (reusing && targetId) {
try { await cdp.send('Target.closeTarget', { targetId }, { timeoutMs: 5_000 }); } catch {}
}
cdp.close();
}
if (chrome) {
if (leaveChromeOpen) {
chrome.unref();
} else {
await gracefulKillChrome(chrome, port);
}
}
}
}
function printUsage(): never {
console.log(`Quote a tweet on X (Twitter) using real Chrome browser
Usage:
npx -y bun x-quote.ts <twe
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
n for 30 seconds for preview...');
await sleep(30_000);
}
} finally {
let leaveChromeOpen = false;
if (chrome && loggedInDuringRun && cdp && sessionId) {
console.log('[x-quote] Waiting for X session cookies to persist...');
const sessionReady = await waitForXSessionPersistence({ cdp, sessionId });
if (!sessionReady) {
console.warn('[x-quote] X session cookies not observed yet. Leaving Chrome open so login can finish persisting.');
leaveChromeOpen = true;
}
}
if (cdp) {
if (reusing && targetId) {
try { await cdp.send('Target.closeTarget', { targetId }, { timeoutMs: 5_000 }); } catch {}
}
cdp.close();
}
if (chrome) {
if (leaveChromeOpen) {
chrome.unref();
} else {
await gracefulKillChrome(chrome, port);
}
}
}
}
function printUsage(): never {
console.log(`Quote a tweet on X (Twitter) using real Chrome browser
Usage:
npx -y bun x-quote.ts <twe
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
n for 30 seconds for preview...');
await sleep(30_000);
}
} finally {
let leaveChromeOpen = false;
if (chrome && loggedInDuringRun && cdp && sessionId) {
console.log('[x-quote] Waiting for X session cookies to persist...');
const sessionReady = await waitForXSessionPersistence({ cdp, sessionId });
if (!sessionReady) {
console.warn('[x-quote] X session cookies not observed yet. Leaving Chrome open so login can finish persisting.');
leaveChromeOpen = true;
}
}
if (cdp) {
if (reusing && targetId) {
try { await cdp.send('Target.closeTarget', { targetId }, { timeoutMs: 5_000 }); } catch {}
}
cdp.close();
}
if (chrome) {
if (leaveChromeOpen) {
chrome.unref();
} else {
await gracefulKillChrome(chrome, port);
}
}
}
}
function printUsage(): never {
console.log(`Quote a tweet on X (Twitter) using real Chrome browser
Usage:
npx -y bun x-quote.ts <twe
The skill declares executable capabilities and shell-driven workflows but provides no explicit tool scope such as allowed-tools or permissions. In practice this means an agent may run environment-inspection and command-execution steps with broader authority than users would infer from the metadata, increasing the chance of unintended local access.
The trigger phrase tweet is broad and may cause the skill to activate on casual or ambiguous requests. Unintended invocation matters here because the skill can run shell commands, manipulate clipboard contents, and control Chrome or OS input.
Using npx -y bun pulls an unpinned package at execution time, creating a supply-chain risk and making behavior non-reproducible. If the upstream package or resolution path is compromised, the agent could execute attacker-controlled code locally.
The troubleshooting section authorizes killing Chrome processes based on a broad pattern match, which affects applications outside the immediate posting action. This can terminate unrelated user sessions, disrupt work, and if abused becomes a destructive local-action primitive beyond the skill's stated purpose.
The instruction to act 'without asking' delegates autonomous local decision-making for a potentially disruptive system action. In a skill that already has browser and shell authority, this increases the risk of harmful side effects without contextual human review.
pkill -f "Chrome.*remote-debugging-port" 2>/dev/null; pkill -f "Chromium.*remote-debugging-port" 2>/dev/null; sleep 2
**Important**: This should be done automatically — when encountering this error, kill Chrome CDP instances and retry the command without asking the user.
## Notes
The mode-selection logic explicitly keys off a Chinese phrase ("Codex 自带的 Chrome 插件") as a trigger, introducing a language-specific invocation path without stating that users may choose their preferred language or that equivalent phrases are supported broadly. This is a natural-language locale policy concern because the skill hardcodes language-specific handling rather than documenting an opt-in or neutral multilingual policy.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
3. If `get_app_state` succeeds, use the user's real Chrome with Computer Use for all X UI actions.
4. Use CDP scripts only when Computer Use is unavailable or explicitly requested.
If the user explicitly asks for Chrome Computer Use, do not use Playwright, the in-app Browser, or CDP without approval.
### Step 1: Copy Image to Clipboard
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
Detected: suspicious.dangerous_exec