T01 · Skill Instruction Hijacking
- Location
references/analyst_prompt_template.md:59- Finding
Indirect Prompt Injection Through Untrusted Tweet Content
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill does what it says at a high level, but it asks for sensitive X browser session credentials and does not clearly limit or protect how they are used.
Review this carefully before installing. Use only a trusted `bird` CLI source, avoid putting `AUTH_TOKEN` and `CT0` in persistent shell profiles or logs, consider rotating/revoking the X session after use, and do not rely on the advertised time-range filtering unless it is fixed. Run digest generation in a tool-limited context because tweets can contain prompt-injection text.
references/analyst_prompt_template.md:59Indirect Prompt Injection Through Untrusted Tweet Content
scripts/fetch_followings_tweets.sh:21Unpinned External CLI Executes With X Session Credentials in Its Environment
The core fetching behavior roughly matches the description's tweet-collection aspect, including reliance on X auth environment variables. However, the description's primary promise includes generating a structured AI digest, which this code does not do at all—it only returns tweet JSON. Additionally, although the script accepts a day count and computes a past timestamp, it does not use that timestamp to filter results; the comments even note that precise time filtering may not be supported. So the declared time-range support is materially overstated. This is a description-behavior mismatch, though not because of any hidden or unrelated capability.
The skill instructs users to export browser-cookie-derived X credentials (AUTH_TOKEN and CT0) and automate access to followings' tweets without clear warnings about credential sensitivity, account takeover risk, or privacy implications. Because these tokens often grant authenticated session access, mishandling them in shell history, logs, shared environments, or downstream tools could expose the user's X account and private account activity.
The script silently relies on AUTH_TOKEN and CT0 and performs a network-backed fetch of a user's followings timeline without any explicit runtime disclosure, consent prompt, or minimization controls. In the context of an agent skill that can be triggered by natural-language requests, this increases privacy risk because sensitive account-scoped data may be retrieved and processed unexpectedly.
The manifest says the skill supports 1/3/7-day or custom ranges for fetching recent followings' tweets. In the code, a timestamp is computed at L19 but never used, and the script simply returns the latest tweets from bird following while only annotating the output with the requested days value at L31. This means the described time-bounded behavior is not implemented.
The comment at L29 says that when days are specified, tweets will be filtered, albeit in a simplified way. However, the code at L30-L31 does not inspect tweet timestamps or apply any filtering logic; it only wraps the unfiltered tweet set with days and limit metadata. This is an active contradiction between documentation and behavior.
The instruction '中文输出,技术术语保留英文' forces a specific output language in that mode. Under the policy rule, locale or language constraints should be user-selected or clearly offered as an option rather than imposed without opt-in.
The instruction 'English output, keep technical terms as-is' requires a specific language for output. This is a language-policy concern unless the template clearly frames the language as chosen by the user or optional.
Comments describing the script's purpose, usage, example, and output are written only in Chinese. This imposes a specific language on users without offering an alternative or documenting a locale-specific constraint.
No suspicious patterns detected.