T01 · Skill Instruction Hijacking
- Location
SKILL.md:27- Finding
Forced Execution and Unverified Authorization for Authenticated Account Actions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill openly automates X/Twitter follows and replies, but it pushes agents to act from the logged-in account immediately without enough confirmation, account verification, or targeting safeguards.
Review this before installing if you care about controlling exactly what your X account follows or posts. It should only be used with an account you intentionally logged in for this purpose, and you should add or require explicit confirmation, active-account verification, per-run limits, and preview approval for every public reply before allowing it to run.
SKILL.md:27Forced Execution and Unverified Authorization for Authenticated Account Actions
SKILL.md:92Autonomous Publication of Unsolicited Growth Comments Without Per-Target Approval
scripts/follow_back.sh:43Ambiguous Snapshot Matching Can Click Unintended Follow or Publish Controls
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The description claims a multi-function Twitter growth skill covering mutual follows, following back followers, commenting, and autonomous greeting for growth. The supplied code only implements one narrow capability: posting a reply to a specific tweet URL with user-provided text. While commenting is part of the declared description, the actual code does not support the other prominently claimed behaviors, nor does it autonomously find targets or manage follower/follow-back workflows. This is a material description-to-behavior mismatch because the declared primary scope is significantly broader than what the code actually does.
The description presents a multi-capability Twitter/X growth automation skill, including 蓝V互关 (verified follower mutual follows), follow-backs, comment generation/posting, and proactive engagement for follower growth. The code chunk, however, is narrowly scoped: it navigates to /followers for the given account, ensures it is not on the verified_followers page, searches for Follow/关注/回关 buttons, and clicks them up to MAX times. It explicitly avoids switching to the certified/verified followers tab, which conflicts with the declared 蓝V互关 capability. No code exists for composing comments, finding tweets needing exposure, or posting greetings. So while one declared capability (回关新粉丝) is represented, the supplied code materially under-implements and in one case contradicts the broader declared behavior.
Several listed triggers like '回关', '帮我回关', and '有人关注我了' are ambiguous and lack account, count, or action scope constraints. Because the skill is designed to act immediately and modify a live social-media account, these vague triggers raise the risk of unauthorized or mistaken execution.
The trigger phrase '今天做下推特运营' and similar broad activators can cause the agent to perform account-modifying actions from ordinary conversational requests without sufficiently specific user intent. In a social-account automation skill, ambiguous invocation increases the chance of unintended follows or posts on the user's logged-in account.
The workflow instructs the agent to immediately run follow-back automation that changes the user's X account state, but it does so without a safety warning or confirmation at the moment of execution. This is dangerous because social-account actions are externally visible, may violate platform rules, and can be triggered after minimal input once the user is logged in.
The proactive commenting workflow directs the agent to discover tweets and autonomously post comments from the user's account, yet it lacks a clear warning and per-post approval requirement. Autonomous posting is more dangerous than passive browsing because it creates public content, can impersonate the user's views, and may cause reputational harm, spam complaints, or account enforcement if comments are posted at scale.
The script performs an irreversible external action—posting a reply on X—immediately after typing content, with no explicit confirmation, dry-run mode, or final user approval. In the context of a social-media automation skill designed to increase engagement and followers, this increases the risk of accidental posting, unwanted account activity, policy violations, or abuse if upstream inputs are manipulated.
The script performs account-modifying follow actions immediately once run, with no interactive confirmation, dry-run mode, or warning before clicking Follow/关注 buttons. In this skill’s context, the behavior is explicitly designed to automate social-media growth actions on a logged-in X account, which makes accidental or excessive follows more likely and can lead to unintended account state changes, platform policy violations, or reputational damage.
The script's natural-language comments and console messages are presented in Chinese only, including usage and operational prompts. This imposes a specific language on users without offering a language choice or documenting that the skill is intentionally locale-specific.
No suspicious patterns detected.