Back to skill

Security audit

X Alive

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent X/Twitter automation playbook, but it enables recurring account-affecting posting and replies with weak approval and credential-handling guidance.

Review before installing. Use this only with explicit operator policies for what the agent may post, reply to, quote, pin, or ignore; require approval for public write actions until trust is established. Store X credentials in a secret manager or restrict env-file permissions, and pin or audit the x-research dependency before giving it access to tokens.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
README.md:68
Finding

Bearer Token Stored in a Plaintext File Without Explicit Access Controls

Content
View full analysis
~/.config/env/global.env ``` ### Technical Analysis The setup instructions persist an X bearer token in `~/.config/env/global.env` using ordinary shell redirection. Neither the directory nor the resulting file is assigned an explicit restrictive permission mode. The effective permissions therefore depend on the operator's current `umask`. On systems using a permissive configuration, the credential file may be readable by other local users, services, backup agents, indexing tools, or processes running under a shared account. The token is legitimately required for the Skill's X search and read operations. The security issue is not its use against X, but its unprotected persistence in a general-purpose plaintext configuration file. The documented command may also encourage users to place a real token directly into an interactive shell command, potentially leaving it in shell history. ### Attack Path 1. An operator follows the documented setup instructions and writes a valid X bearer token to `~/.config/env/global.env`. 2. The file is created under the operator's default `umask` without an explicit `0600` mode. 3. A local user, compromised process, backup service, or other component with access to the home directory reads the file. 4. The attacker extracts `X_BEARER_TOKEN`. 5. The attacker submits the token to X API endpoints and exercises the API permissions associated with that credential until it is revoked or expires. This path requires local filesystem access or access through another service that can read the file; the project does not itself transmit the token to an unauthorized host. ### Impact Assessment A successful attacker can obtain the ...[truncated 646 chars]
Remediation
View remediation
"$HOME/.config/env/global.env" ``` 3. Verify the permissions after creation: ```bash chmod 700 "$HOME/.config/env" chmod 600 "$HOME/.config/env/global.env" ``` 4. Avoid entering real secrets directly into commands retained by shell history. Prefer a hidden prompt, secret-manager injection, or a protected editor. 5. Ensure the credential file is excluded from source control, diagnostics, backups that lack encryption, and application logs. 6. Grant the token only the minimum X API scopes needed for searching and reading. 7. Document token rotation and immediate revocation procedures for suspected disclosure. ]]>

T08 · Insecure Dependencies

Warning
Location
README.md:60
Finding

Unpinned Third-Party Skill Installed Into a Credential-Bearing Agent Environment

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 11)May include surrounding context.

md
A skill (playbook) for AI agents that covers:

- **Identity** — pull from your existing agent persona, don't create a new one
- **Being Online** — check the pulse, engage organically, reply when you have something real to say
- **Dedup** — never post the same topic twice in 24h
- **Mentions & DMs** — when to reply, when to ignore, when to flag your human

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README instructs users to place a live X bearer token into a predictable local file path without any guidance on file permissions, secret-management practices, or avoiding accidental commits and exposure. While common in developer setups, this can lead to credential leakage through weak filesystem permissions, shell history, backups, screenshots, or source-control mistakes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's 'use when' description is very broad and can match many routine social-media tasks, increasing the chance the agent invokes it in situations that involve posting, replying, or account management without sufficiently narrow gating. In this context, over-broad invocation is risky because the skill explicitly enables autonomous account-affecting behavior on a public platform.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 107)May include surrounding context.

md
1. **xurl** — install and configure OAuth 1.0a for posting: `xurl auth oauth1`
2. **x-research** — install the skill and set `X_BEARER_TOKEN` in `~/.config/env/global.env`
3. **Your X user ID** — fetch it: `curl -s "https://api.x.com/2/users/by/username/YOUR_HANDLE" -H "Authorization: Bearer $X_BEARER_TOKEN"` — save this for dedup checks

### Wiring the Loop

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
1. **xurl** — install and configure OAuth 1.0a for posting: `xurl auth oauth1`
2. **x-research** — install the skill and set `X_BEARER_TOKEN` in `~/.config/env/global.env`
3. **Your X user ID** — fetch it: `curl -s "https://api.x.com/2/users/by/username/YOUR_HANDLE" -H "Authorization: Bearer $X_BEARER_TOKEN"` — save this for dedup checks

### Wiring the Loop

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to run a recurring loop that may autonomously engage or post on X, but it does not place a strong, upfront warning or mandatory confirmation around account-impacting actions. Because these actions are public, persistent, and reputationally sensitive, an agent could cause unwanted posts, replies, or behavioral drift without the operator's immediate awareness.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.