Back to skill

Security audit

Baoyu Post To X

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with posting to X, but it needs review because it combines public posting automation with clipboard/keystroke control, broad process-kill recovery, and unpinned runtime execution.

Install only if you are comfortable granting an agent control over your real Chrome/X session, clipboard, file picker, and paste keystrokes. Review every post before publishing, avoid the --submit path unless you explicitly intend to publish, do not process untrusted Markdown with remote images, and prefer a preinstalled trusted Bun runtime instead of the npx fallback. Be especially cautious with the automatic Chrome process-kill troubleshooting instruction.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/paste-from-clipboard.ts:35
Finding

AppleScript Injection Through the Unescaped Target Application Name

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/x-utils.ts:257
Finding

Automatic Execution of an Unpinned Bun Package Through npx

Content
View full analysis
{ const result = spawnSync('npx', ['-y', 'bun', '--version'], { stdio: 'pipe', timeout: 30_000 }); if (result.status === 0) { log('Bun runtime', true, `v${result.stdout?.toString().trim()}`); } else { log('Bun runtime', false, 'Cannot run bun. Install: brew install oven-sh/bun/bun (macOS) or npm install -g bun'); } } ``` The Skill instructions explicitly recommend this fallback: ```md 4. Resolve `${BUN_X}` runtime: if `bun` installed → `bun`; if `npx` available → `npx -y bun`; else suggest installing bun ``` ### Technical Analysis `npx -y bun` can retrieve the registry-selected version of the `bun` package and execute it immediately without interactive approval. No exact package version is supplied, and this runtime package is not pinned by the project lockfile. The `-y` option suppresses the normal installation prompt. Consequently, the effective code being executed can change after the Skill has been reviewed. The integrity entries in `scripts/bun.lock` cover the declared project dependencies, but they do not pin the separate package downloaded by these `npx` invocations. This creates a supply-chain execution boundary controlled by the configured npm registry and the current state of the package name. A registry compromise, package-account takeover, malicious registry mirror, DNS/proxy manipulation, or unexpected package relea ...[truncated 1125 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/x-article.ts:76
Finding

Predictable Shared Temporary File Allows Symlink-Based File Overwrite

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/md-to-html.ts:286
Finding

Unrestricted Remote Markdown Image Resolution Creates an SSRF-Capable Workflow

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (66)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill documents OS-level clipboard and keystroke automation, including frontmost-application interaction, which is more powerful than a simple social-posting abstraction suggests. Such automation can affect whatever window has focus and may interact with unrelated apps or sensitive content if context is wrong.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill documents OS-level clipboard and keystroke automation, including frontmost-application interaction, which is more powerful than a simple social-posting abstraction suggests. Such automation can affect whatever window has focus and may interact with unrelated apps or sensitive content if context is wrong.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill documents OS-level clipboard and keystroke automation, including frontmost-application interaction, which is more powerful than a simple social-posting abstraction suggests. Such automation can affect whatever window has focus and may interact with unrelated apps or sensitive content if context is wrong.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill documents OS-level clipboard and keystroke automation, including frontmost-application interaction, which is more powerful than a simple social-posting abstraction suggests. Such automation can affect whatever window has focus and may interact with unrelated apps or sensitive content if context is wrong.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill documents OS-level clipboard and keystroke automation, including frontmost-application interaction, which is more powerful than a simple social-posting abstraction suggests. Such automation can affect whatever window has focus and may interact with unrelated apps or sensitive content if context is wrong.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill documents OS-level clipboard and keystroke automation, including frontmost-application interaction, which is more powerful than a simple social-posting abstraction suggests. Such automation can affect whatever window has focus and may interact with unrelated apps or sensitive content if context is wrong.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill documents OS-level clipboard and keystroke automation, including frontmost-application interaction, which is more powerful than a simple social-posting abstraction suggests. Such automation can affect whatever window has focus and may interact with unrelated apps or sensitive content if context is wrong.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill documents OS-level clipboard and keystroke automation, including frontmost-application interaction, which is more powerful than a simple social-posting abstraction suggests. Such automation can affect whatever window has focus and may interact with unrelated apps or sensitive content if context is wrong.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
| `scripts/x-article.ts` | Long-form article publishing (Markdown), CDP fallback |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 300)May include surrounding context.

md
| `scripts/x-article.ts` | Long-form article publishing (Markdown), CDP fallback |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
| `scripts/check-paste-permissions.ts` | Verify environment & permissions |

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs the agent to kill Chrome CDP instances and retry without user warning or approval. Silent destructive actions on local processes violate least surprise and can interrupt unrelated tasks, especially because the match pattern is broad and not limited to processes started by the skill.

Content

No source excerpt is available for this finding.

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/x-browser.ts (reported line 199)May include surrounding context.

ts
n for 30 seconds for preview...');
      await sleep(30_000);
    }
  } finally {
    let leaveChromeOpen = false;
    if (chrome && loggedInDuringRun && cdp && sessionId) {
      console.log('[x-quote] Waiting for X session cookies to persist...');
      const sessionReady = await waitForXSessionPersistence({ cdp, sessionId });
      if (!sessionReady) {
        console.warn('[x-quote] X session cookies not observed yet. Leaving Chrome open so login can finish persisting.');
        leaveChromeOpen = true;
      }
    }

    if (cdp) {
      if (reusing && targetId) {
        try { await cdp.send('Target.closeTarget', { targetId }, { timeoutMs: 5_000 }); } catch {}
      }
      cdp.close();
    }
    if (chrome) {
      if (leaveChromeOpen) {
        chrome.unref();
      } else {
        await gracefulKillChrome(chrome, port);
      }
    }
  }
}

function printUsage(): never {
  console.log(`Quote a tweet on X (Twitter) using real Chrome browser

Usage:
  npx -y bun x-quote.ts <twe

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/x-quote.ts (reported line 186)May include surrounding context.

ts
n for 30 seconds for preview...');
      await sleep(30_000);
    }
  } finally {
    let leaveChromeOpen = false;
    if (chrome && loggedInDuringRun && cdp && sessionId) {
      console.log('[x-quote] Waiting for X session cookies to persist...');
      const sessionReady = await waitForXSessionPersistence({ cdp, sessionId });
      if (!sessionReady) {
        console.warn('[x-quote] X session cookies not observed yet. Leaving Chrome open so login can finish persisting.');
        leaveChromeOpen = true;
      }
    }

    if (cdp) {
      if (reusing && targetId) {
        try { await cdp.send('Target.closeTarget', { targetId }, { timeoutMs: 5_000 }); } catch {}
      }
      cdp.close();
    }
    if (chrome) {
      if (leaveChromeOpen) {
        chrome.unref();
      } else {
        await gracefulKillChrome(chrome, port);
      }
    }
  }
}

function printUsage(): never {
  console.log(`Quote a tweet on X (Twitter) using real Chrome browser

Usage:
  npx -y bun x-quote.ts <twe

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/x-video.ts (reported line 193)May include surrounding context.

ts
n for 30 seconds for preview...');
      await sleep(30_000);
    }
  } finally {
    let leaveChromeOpen = false;
    if (chrome && loggedInDuringRun && cdp && sessionId) {
      console.log('[x-quote] Waiting for X session cookies to persist...');
      const sessionReady = await waitForXSessionPersistence({ cdp, sessionId });
      if (!sessionReady) {
        console.warn('[x-quote] X session cookies not observed yet. Leaving Chrome open so login can finish persisting.');
        leaveChromeOpen = true;
      }
    }

    if (cdp) {
      if (reusing && targetId) {
        try { await cdp.send('Target.closeTarget', { targetId }, { timeoutMs: 5_000 }); } catch {}
      }
      cdp.close();
    }
    if (chrome) {
      if (leaveChromeOpen) {
        chrome.unref();
      } else {
        await gracefulKillChrome(chrome, port);
      }
    }
  }
}

function printUsage(): never {
  console.log(`Quote a tweet on X (Twitter) using real Chrome browser

Usage:
  npx -y bun x-quote.ts <twe

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares executable capabilities and shell-driven workflows but provides no explicit tool scope such as allowed-tools or permissions. In practice this means an agent may run environment-inspection and command-execution steps with broader authority than users would infer from the metadata, increasing the chance of unintended local access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The trigger phrase tweet is broad and may cause the skill to activate on casual or ambiguous requests. Unintended invocation matters here because the skill can run shell commands, manipulate clipboard contents, and control Chrome or OS input.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

Using npx -y bun pulls an unpinned package at execution time, creating a supply-chain risk and making behavior non-reproducible. If the upstream package or resolution path is compromised, the agent could execute attacker-controlled code locally.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The troubleshooting section authorizes killing Chrome processes based on a broad pattern match, which affects applications outside the immediate posting action. This can terminate unrelated user sessions, disrupt work, and if abused becomes a destructive local-action primitive beyond the skill's stated purpose.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
93% confidence
Finding

The instruction to act 'without asking' delegates autonomous local decision-making for a potentially disruptive system action. In a skill that already has browser and shell authority, this increases the risk of harmful side effects without contextual human review.

Content

Scanner excerpt · SKILL.md (reported line 324)May include surrounding context.

pkill -f "Chrome.*remote-debugging-port" 2>/dev/null; pkill -f "Chromium.*remote-debugging-port" 2>/dev/null; sleep 2

text

**Important**: This should be done automatically — when encountering this error, kill Chrome CDP instances and retry the command without asking the user.

## Notes

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The mode-selection logic explicitly keys off a Chinese phrase ("Codex 自带的 Chrome 插件") as a trigger, introducing a language-specific invocation path without stating that users may choose their preferred language or that equivalent phrases are supported broadly. This is a natural-language locale policy concern because the skill hardcodes language-specific handling rather than documenting an opt-in or neutral multilingual policy.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/regular-posts.md (reported line 18)May include surrounding context.

md
3. If `get_app_state` succeeds, use the user's real Chrome with Computer Use for all X UI actions.
4. Use CDP scripts only when Computer Use is unavailable or explicitly requested.

If the user explicitly asks for Chrome Computer Use, do not use Playwright, the in-app Browser, or CDP without approval.

### Step 1: Copy Image to Clipboard

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/copy-to-clipboard.ts:59

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/paste-from-clipboard.ts:107

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/x-utils.ts:90