Back to skill

Security audit

📰 ZeeLin Report-to-X AutoPost

Security checks for vulnerabilities and agentic risk

Overview

The skill’s report-to-X automation is mostly disclosed, but it delegates posting to an unverified external shell script and can publish publicly or schedule recurring posts without a clear confirmation gate.

Review before installing. This skill can post publicly to the X account already logged in on the machine and may be used with cron for recurring posts. Only use it if you trust the external tweet.sh script it calls, understand which X account/session it will use, and are comfortable with unattended public posting and local posting-history state.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/post_daily_report.py:6
Finding

Execution of an Unverified External Shell Script

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/post_daily_report.py:52
Finding

Failed Publication Is Unconditionally Recorded as Successful

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (10)

Tainted flow: 'tweet' from requests.get (line 51, network input) → subprocess.run (code execution)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

External input (network, user) flows to a code execution sink. This enables remote code execution or command injection.

Content

Scanner excerpt · scripts/post_daily_report.py (reported line 53)May include surrounding context.

python
tweet = f"New AI research report released.\n\n{latest}\n\n{summary}\n\nReport:\n{REPORT_SITE}\n\n#AI #TechTwitter"

subprocess.run(["bash", TWEET_SCRIPT, tweet, "https://x.com"], check=False)

posted.add(latest)
with open(STATE_FILE, "w") as f:

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The code largely matches the core declared purpose: it fetches the latest unposted report from a website, drafts an English X post, calls a separate script to publish it via X, and records prior posts to avoid duplicates. However, there are material gaps versus the description. The implementation only handles a hardcoded HTML website and contains no JSON feed support. It stores posted report titles, not IDs. Also, this chunk itself does not implement scheduling, though that may be external. These differences are enough to mark a partial mismatch, even though the primary purpose is substantially aligned.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill clearly instructs use of network access, shell execution, and file writes, but it declares no explicit tool scope or permissions. That creates an overbroad execution surface where an agent may use more capabilities than the user expects, especially because the workflow includes external posting and state persistence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is designed to perform automated external actions, including posting to X and setting up scheduled cron execution, but it does not require an explicit warning or confirmation step. This increases the risk of unintended public posting or persistent automation being launched without sufficiently informed user consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The activation section lists example requests such as '自动把最新报告发到 X' and '帮我把报告站做成自动社媒分发', but it does not define what kinds of sources, posting scopes, or user intents should not invoke the skill. This ambiguity could cause the skill to be selected for loosely related social-media automation requests beyond the intended report-to-X workflow.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/post_daily_report.py (reported line 53)May include surrounding context.

python
tweet = f"New AI research report released.\n\n{latest}\n\n{summary}\n\nReport:\n{REPORT_SITE}\n\n#AI #TechTwitter"

subprocess.run(["bash", TWEET_SCRIPT, tweet, "https://x.com"], check=False)

posted.add(latest)
with open(STATE_FILE, "w") as f:

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes selecting a report, drafting a post, and publishing via the logged-in X web session. While posting to X is in scope, invoking an external bash script adds a general subprocess-execution capability that is not itself justified or disclosed by the stated purpose, and it delegates sensitive behavior outside the visible Python logic.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script publishes to a logged-in X session automatically with no confirmation, dry-run, or explicit user-visible warning in the code path. In a scheduled automation context, that makes remote website content capable of triggering unintended public posts, including reputationally damaging or policy-violating messages if the source site is compromised or parsing is manipulated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction '默认英文发帖:除非用户要求中文或双语' imposes a language default rather than asking the user to choose their preferred language first. This is a natural-language policy issue because it forces a locale/language behavior without explicit user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The script writes posting history to ~/.openclaw/memory/zeelin_last_report.json at L56-L57, which affects user data on disk. This file includes no visible warning, prompt, or explanatory docstring/comment telling the user that local state will be created and updated.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.