Back to skill

Security audit

Last 30 Days

Security checks for vulnerabilities and agentic risk

Overview

This is a real research skill, but it needs review because it uses browser login cookies for X and stores research results locally with under-disclosed dependency and file-handling risks.

Install only if you are comfortable with the skill reading X browser session cookies and writing research topics/results to local files. Prefer explicit API-key or manually supplied-token modes, audit or pin the missing cookie dependency before enabling X cookie auth, and avoid sensitive topics on shared machines until output permissions and temp-file handling are fixed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
scripts/lib/vendor/bird-search/lib/cookies.js:1
Finding

Unpinned and Undeclared Browser-Cookie Dependency Can Be Resolved from an Untrusted Location

Content
View full analysis
=22" }, "license": "MIT", "attribution": "Based on @steipete/bird v0.8.0 by Peter Steinberger (MIT License)" } ``` ### Technical Analysis The X search component is represented as a self-contained vendored client, but its cookie-extraction module imports `@steipete/sweet-cookie` without declaring the package in `package.json`, supplying a lockfile, or including the expected package in the audited project. Node.js resolves package imports by searching applicable `node_modules` directories, including ancestor locations. Consequently, an ambient package outside the audited Skill directory may satisfy this import. The loaded package is invoked with access to browser cookie stores and is expected to return X/Twitter authentication cookies: ```javascript const { cookies, warnings: providerWarnings } = await getCookies({ url: TWITTER_URL, origins: TWITTER_ORIGINS, names: [...TWITTER_COOKIE_NAMES], browsers: [options.source], mode: 'merge', chromeProfile: options.chromeProfile, firefoxProfile: options.firefoxProfile, timeoutMs: options.cookieTimeoutMs, }); ``` This creates a dependency-confusion and lo ...[truncated 1868 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/lib/render.py:10
Finding

Research Topics and Raw Provider Responses Are Persisted with Unsafe Default and Temporary-Directory Handling

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (188)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 27)May include surrounding context.

md
# Add your API keys
mkdir -p ~/.config/last30days
cat > ~/.config/last30days/.env << 'EOF'
OPENAI_API_KEY=sk-...
XAI_API_KEY=xai-...       # optional  - cookie auth is default for X search
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 31)May include surrounding context.

md
# Add your API keys
mkdir -p ~/.config/last30days
cat > ~/.config/last30days/.env << 'EOF'
OPENAI_API_KEY=sk-...
XAI_API_KEY=xai-...       # optional  - cookie auth is default for X search
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL-original.md (reported line 259)May include surrounding context.

md
# Add your API keys
mkdir -p ~/.config/last30days
cat > ~/.config/last30days/.env << 'EOF'
OPENAI_API_KEY=sk-...
XAI_API_KEY=xai-...       # optional  - cookie auth is default for X search
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL-original.md (reported line 390)May include surrounding context.

md
# Add your API keys
mkdir -p ~/.config/last30days
cat > ~/.config/last30days/.env << 'EOF'
OPENAI_API_KEY=sk-...
XAI_API_KEY=xai-...       # optional  - cookie auth is default for X search
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/plans/2026-02-06-feat-last30days-bird-cli-release-plan.md (reported line 259)May include surrounding context.

md
# Add your API keys
mkdir -p ~/.config/last30days
cat > ~/.config/last30days/.env << 'EOF'
OPENAI_API_KEY=sk-...
XAI_API_KEY=xai-...       # optional  - cookie auth is default for X search
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · fixtures/reddit_thread_sample.json (reported line 81)May include surrounding context.

json
# Add your API keys
mkdir -p ~/.config/last30days
cat > ~/.config/last30days/.env << 'EOF'
OPENAI_API_KEY=sk-...
XAI_API_KEY=xai-...       # optional  - cookie auth is default for X search
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/lib/env.py (reported line 48)May include surrounding context.

python
# Add your API keys
mkdir -p ~/.config/last30days
cat > ~/.config/last30days/.env << 'EOF'
OPENAI_API_KEY=sk-...
XAI_API_KEY=xai-...       # optional  - cookie auth is default for X search
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/lib/env.py (reported line 52)May include surrounding context.

python
# Add your API keys
mkdir -p ~/.config/last30days
cat > ~/.config/last30days/.env << 'EOF'
OPENAI_API_KEY=sk-...
XAI_API_KEY=xai-...       # optional  - cookie auth is default for X search
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/lib/env.py (reported line 164)May include surrounding context.

python
# Add your API keys
mkdir -p ~/.config/last30days
cat > ~/.config/last30days/.env << 'EOF'
OPENAI_API_KEY=sk-...
XAI_API_KEY=xai-...       # optional  - cookie auth is default for X search
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/lib/ui.py (reported line 371)May include surrounding context.

python
# Add your API keys
mkdir -p ~/.config/last30days
cat > ~/.config/last30days/.env << 'EOF'
OPENAI_API_KEY=sk-...
XAI_API_KEY=xai-...       # optional  - cookie auth is default for X search
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/lib/ui.py (reported line 414)May include surrounding context.

python
# Add your API keys
mkdir -p ~/.config/last30days
cat > ~/.config/last30days/.env << 'EOF'
OPENAI_API_KEY=sk-...
XAI_API_KEY=xai-...       # optional  - cookie auth is default for X search
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/lib/ui.py (reported line 437)May include surrounding context.

python
# Add your API keys
mkdir -p ~/.config/last30days
cat > ~/.config/last30days/.env << 'EOF'
OPENAI_API_KEY=sk-...
XAI_API_KEY=xai-...       # optional  - cookie auth is default for X search
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

The README states that X search reads existing browser cookies and may prompt for Keychain access, which means the skill's workflow depends on extracting authenticated browser session material for another client. Reusing browser cookies/session tokens outside the browser broadens the attack surface and can enable account/session compromise if the local toolchain, vendored client, or surrounding environment is malicious or later compromised.

Content

Scanner excerpt · README.md (reported line 40)May include surrounding context.

md
**Safari (recommended on Mac):** Just be logged into x.com. No setup needed.

**Chrome:** Works, but macOS will prompt you to allow Keychain access the first time. Click "Allow" (or "Always Allow" to stop future prompts).

**Firefox:** Just be logged into x.com. No setup needed.

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The skill directly instructs creation of a .env file intended to hold API keys, which is a credential-handling operation. Even if the placeholders are blank initially, normalizing secret storage through the agent encourages collection and persistence of sensitive credentials in a location that may later be read, reused, or exposed by other tools or sessions.

Content

Scanner excerpt · SKILL-original.md (reported line 67)May include surrounding context.

bash
mkdir -p ~/.config/last30days
cat > ~/.config/last30days/.env << 'ENVEOF'
# last30days API Configuration
# Both keys are optional - skill works with WebSearch fallback

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

This line is part of the same credential-persistence workflow around the .env file and reinforces storage of secrets on disk. The issue is not the permission command itself but the surrounding pattern of agent-mediated secret-file management.

Content

Scanner excerpt · SKILL-original.md (reported line 78)May include surrounding context.

XAI_API_KEY= ENVEOF

chmod 600 ~/.config/last30days/.env echo "Config created at ~/.config/last30days/.env" echo "Edit to add your API keys for enhanced research."

text

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill declares a narrow, read-only research workflow, but the provided evidence indicates materially broader behavior including local persistence, cache writes, browser-cookie-based X authentication handling, and even support for X write-capable endpoints. That mismatch is dangerous because users and hosting agents may grant trust, permissions, or secrets based on the benign description while the underlying implementation exercises much broader capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill declares a narrow, read-only research workflow, but the provided evidence indicates materially broader behavior including local persistence, cache writes, browser-cookie-based X authentication handling, and even support for X write-capable endpoints. That mismatch is dangerous because users and hosting agents may grant trust, permissions, or secrets based on the benign description while the underlying implementation exercises much broader capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill declares a narrow, read-only research workflow, but the provided evidence indicates materially broader behavior including local persistence, cache writes, browser-cookie-based X authentication handling, and even support for X write-capable endpoints. That mismatch is dangerous because users and hosting agents may grant trust, permissions, or secrets based on the benign description while the underlying implementation exercises much broader capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill declares a narrow, read-only research workflow, but the provided evidence indicates materially broader behavior including local persistence, cache writes, browser-cookie-based X authentication handling, and even support for X write-capable endpoints. That mismatch is dangerous because users and hosting agents may grant trust, permissions, or secrets based on the benign description while the underlying implementation exercises much broader capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill declares a narrow, read-only research workflow, but the provided evidence indicates materially broader behavior including local persistence, cache writes, browser-cookie-based X authentication handling, and even support for X write-capable endpoints. That mismatch is dangerous because users and hosting agents may grant trust, permissions, or secrets based on the benign description while the underlying implementation exercises much broader capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill declares a narrow, read-only research workflow, but the provided evidence indicates materially broader behavior including local persistence, cache writes, browser-cookie-based X authentication handling, and even support for X write-capable endpoints. That mismatch is dangerous because users and hosting agents may grant trust, permissions, or secrets based on the benign description while the underlying implementation exercises much broader capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill declares a narrow, read-only research workflow, but the provided evidence indicates materially broader behavior including local persistence, cache writes, browser-cookie-based X authentication handling, and even support for X write-capable endpoints. That mismatch is dangerous because users and hosting agents may grant trust, permissions, or secrets based on the benign description while the underlying implementation exercises much broader capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill declares a narrow, read-only research workflow, but the provided evidence indicates materially broader behavior including local persistence, cache writes, browser-cookie-based X authentication handling, and even support for X write-capable endpoints. That mismatch is dangerous because users and hosting agents may grant trust, permissions, or secrets based on the benign description while the underlying implementation exercises much broader capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill declares a narrow, read-only research workflow, but the provided evidence indicates materially broader behavior including local persistence, cache writes, browser-cookie-based X authentication handling, and even support for X write-capable endpoints. That mismatch is dangerous because users and hosting agents may grant trust, permissions, or secrets based on the benign description while the underlying implementation exercises much broader capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill declares a narrow, read-only research workflow, but the provided evidence indicates materially broader behavior including local persistence, cache writes, browser-cookie-based X authentication handling, and even support for X write-capable endpoints. That mismatch is dangerous because users and hosting agents may grant trust, permissions, or secrets based on the benign description while the underlying implementation exercises much broader capabilities.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/lib/vendor/bird-search/lib/twitter-client-base.js:38

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/lib/vendor/bird-search/bird-search.mjs:96

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/lib/vendor/bird-search/lib/cookies.js:134

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/lib/vendor/bird-search/lib/twitter-client-base.js:19