Back to skill

Security audit

X Followings Digest

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says at a high level, but it asks for sensitive X browser session credentials and does not clearly limit or protect how they are used.

Review this carefully before installing. Use only a trusted `bird` CLI source, avoid putting `AUTH_TOKEN` and `CT0` in persistent shell profiles or logs, consider rotating/revoking the X session after use, and do not rely on the advertised time-range filtering unless it is fixed. Run digest generation in a tool-limited context because tweets can contain prompt-injection text.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
references/analyst_prompt_template.md:59
Finding

Indirect Prompt Injection Through Untrusted Tweet Content

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/fetch_followings_tweets.sh:21
Finding

Unpinned External CLI Executes With X Session Credentials in Its Environment

Content
View full analysis
/dev/null) ``` `SKILL.md:76-78`: ```markdown - `bird` CLI (X/Twitter client) - `AUTH_TOKEN` & `CT0` from browser cookies ``` ### Technical Analysis The script executes the first program named `bird` resolved through the process environment's `PATH`. The project does not identify an authoritative package source, pin a version, verify a checksum or signature, or validate the resolved executable. The required `AUTH_TOKEN` and `CT0` values are exported environment variables. Child processes normally inherit exported environment variables, so the selected `bird` executable can access these X session credentials even though they are not included as command-line arguments. Authenticated network access is necessary for the declared private-followings functionality. However, entrusting high-value browser session cookies to an unspecified executable creates avoidable supply-chain and PATH-hijacking risk. No malicious dependency or actual credential exfiltration is present in the reviewed project; exploitation requires a malicious, substituted, or compromised `bird` executable. ### Attack Path 1. A user installs a malicious or incorrectly sourced package that provides an executable named `bird`, or an attacker with local write access places a malicious executable earlier in `PATH`. 2. The user exports `AUTH_TOKEN` and `CT0` as required by the Skill. 3. The script resolves and launches the attacker-controlled `bird` executable. 4. The executable reads the inherited environment variables. 5. It transmits the X session credentials to an attacker-controlled endpoint or uses them directly. 6. The mali ...[truncated 752 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The core fetching behavior roughly matches the description's tweet-collection aspect, including reliance on X auth environment variables. However, the description's primary promise includes generating a structured AI digest, which this code does not do at all—it only returns tweet JSON. Additionally, although the script accepts a day count and computes a past timestamp, it does not use that timestamp to filter results; the comments even note that precise time filtering may not be supported. So the declared time-range support is materially overstated. This is a description-behavior mismatch, though not because of any hidden or unrelated capability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs users to export browser-cookie-derived X credentials (AUTH_TOKEN and CT0) and automate access to followings' tweets without clear warnings about credential sensitivity, account takeover risk, or privacy implications. Because these tokens often grant authenticated session access, mishandling them in shell history, logs, shared environments, or downstream tools could expose the user's X account and private account activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script silently relies on AUTH_TOKEN and CT0 and performs a network-backed fetch of a user's followings timeline without any explicit runtime disclosure, consent prompt, or minimization controls. In the context of an agent skill that can be triggered by natural-language requests, this increases privacy risk because sensitive account-scoped data may be retrieved and processed unexpectedly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says the skill supports 1/3/7-day or custom ranges for fetching recent followings' tweets. In the code, a timestamp is computed at L19 but never used, and the script simply returns the latest tweets from bird following while only annotating the output with the requested days value at L31. This means the described time-bounded behavior is not implemented.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The comment at L29 says that when days are specified, tweets will be filtered, albeit in a simplified way. However, the code at L30-L31 does not inspect tweet timestamps or apply any filtering logic; it only wraps the unfiltered tweet set with days and limit metadata. This is an active contradiction between documentation and behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction '中文输出,技术术语保留英文' forces a specific output language in that mode. Under the policy rule, locale or language constraints should be user-selected or clearly offered as an option rather than imposed without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction 'English output, keep technical terms as-is' requires a specific language for output. This is a language-policy concern unless the template clearly frames the language as chosen by the user or optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

Comments describing the script's purpose, usage, example, and output are written only in Chinese. This imposes a specific language on users without offering an alternative or documenting a locale-specific constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.