Back to skill

Security audit

ZeeLin Twitter/X 运营

Security checks for vulnerabilities and agentic risk

Overview

The skill openly automates X/Twitter follows and replies, but it pushes agents to act from the logged-in account immediately without enough confirmation, account verification, or targeting safeguards.

Review this before installing if you care about controlling exactly what your X account follows or posts. It should only be used with an account you intentionally logged in for this purpose, and you should add or require explicit confirmation, active-account verification, per-run limits, and preview approval for every public reply before allowing it to run.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:27
Finding

Forced Execution and Unverified Authorization for Authenticated Account Actions

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:92
Finding

Autonomous Publication of Unsolicited Growth Comments Without Per-Target Approval

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/follow_back.sh:43
Finding

Ambiguous Snapshot Matching Can Click Unintended Follow or Publish Controls

Content
View full analysis
/dev/null) REF=$(echo "$SNAP" | grep -E 'button.*"Follow"' | grep -v 'Following' | grep -oE 'ref=e[0-9]+' | head -1 | sed 's/ref=//') ``` They also use increasingly broad fallback searches equivalent to: ```bash REF=$(echo "$SNAP" | grep -E 'Follow' | grep -v 'Following' | grep -oE 'ref=e[0-9]+' | head -1 | sed 's/ref=//') REF=$(echo "$SNAP" | grep -B2 -E 'Follow' | grep -v 'Following' | grep -oE 'ref=e[0-9]+' | tail -1 | sed 's/ref=//') REF=$(echo "$SNAP" | grep -E 'cursor=pointer.*Follow|Follow.*cursor=pointer' | grep -v Following | grep -oE 'ref=e[0-9]+' | head -1 | sed 's/ref=//') ``` The comment script similarly chooses the first enabled reply- or post-like control in the entire page snapshot: ```bash SNAP2=$($CLI snapshot 2>/dev/null) BTN=$(echo "$SNAP2" | grep -iE 'button.*[Rr]eply|button.*[Pp]ost' | grep -v 'disabled' | grep -oE 'ref=e[0-9]+' | head -1 | sed 's/ref=//') if [ -z "$BTN" ]; then echo " Trying Cmd+Enter to submit" $CLI press "Meta+Enter" 2>/dev/null else $CLI click "$BTN" 2>/dev/null fi ``` The excerpts above preserve the operative matching behavior while rendering non-English labels and messages in English. ### Technical Analysis The scripts parse a textual browser snapshot with `grep`, extract a generic element reference, and click the first or last matching result. The selected reference is not bound to: - A specific follower row. - A verified target username. - A specific tweet or reply composer. - A stable semantic element identifier. - A validated page contai ...[truncated 2383 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description claims a multi-function Twitter growth skill covering mutual follows, following back followers, commenting, and autonomous greeting for growth. The supplied code only implements one narrow capability: posting a reply to a specific tweet URL with user-provided text. While commenting is part of the declared description, the actual code does not support the other prominently claimed behaviors, nor does it autonomously find targets or manage follower/follow-back workflows. This is a material description-to-behavior mismatch because the declared primary scope is significantly broader than what the code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description presents a multi-capability Twitter/X growth automation skill, including 蓝V互关 (verified follower mutual follows), follow-backs, comment generation/posting, and proactive engagement for follower growth. The code chunk, however, is narrowly scoped: it navigates to /followers for the given account, ensures it is not on the verified_followers page, searches for Follow/关注/回关 buttons, and clicks them up to MAX times. It explicitly avoids switching to the certified/verified followers tab, which conflicts with the declared 蓝V互关 capability. No code exists for composing comments, finding tweets needing exposure, or posting greetings. So while one declared capability (回关新粉丝) is represented, the supplied code materially under-implements and in one case contradicts the broader declared behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Several listed triggers like '回关', '帮我回关', and '有人关注我了' are ambiguous and lack account, count, or action scope constraints. Because the skill is designed to act immediately and modify a live social-media account, these vague triggers raise the risk of unauthorized or mistaken execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase '今天做下推特运营' and similar broad activators can cause the agent to perform account-modifying actions from ordinary conversational requests without sufficiently specific user intent. In a social-account automation skill, ambiguous invocation increases the chance of unintended follows or posts on the user's logged-in account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow instructs the agent to immediately run follow-back automation that changes the user's X account state, but it does so without a safety warning or confirmation at the moment of execution. This is dangerous because social-account actions are externally visible, may violate platform rules, and can be triggered after minimal input once the user is logged in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The proactive commenting workflow directs the agent to discover tweets and autonomously post comments from the user's account, yet it lacks a clear warning and per-post approval requirement. Autonomous posting is more dangerous than passive browsing because it creates public content, can impersonate the user's views, and may cause reputational harm, spam complaints, or account enforcement if comments are posted at scale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script performs an irreversible external action—posting a reply on X—immediately after typing content, with no explicit confirmation, dry-run mode, or final user approval. In the context of a social-media automation skill designed to increase engagement and followers, this increases the risk of accidental posting, unwanted account activity, policy violations, or abuse if upstream inputs are manipulated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script performs account-modifying follow actions immediately once run, with no interactive confirmation, dry-run mode, or warning before clicking Follow/关注 buttons. In this skill’s context, the behavior is explicitly designed to automate social-media growth actions on a logged-in X account, which makes accidental or excessive follows more likely and can lead to unintended account state changes, platform policy violations, or reputational damage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script's natural-language comments and console messages are presented in Chinese only, including usage and operational prompts. This imposes a specific language on users without offering a language choice or documenting that the skill is intentionally locale-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.