Back to skill

Security audit

A real-time intelligence feed tracking the top 50 AI organizations and influencers globally.

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly aims to generate X/Twitter AI account reports, but it reuses Chrome login cookies through a third-party scraper and overstates automation and data authenticity.

Review this before installing. Use only a dedicated browser profile or test X account if you run the free scraper, avoid exposing your primary Chrome session, and do not rely on the official API mode for real reports until the mock-data path is replaced. Pin dependencies and move credentials to environment or secret storage before operational use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/x-scraper-free.js:91
Finding

Authenticated Browser Session Exposed to a Third-Party Scraper

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/x-monitor.js:9
Finding

Credential-Like X API Material Hard-Coded in Source Code

Content
View full analysis
Remediation
View remediation

other

Warning
Location
scripts/x-monitor.js:49
Finding

Official API Mode Produces Randomized Mock Data as a Daily Report

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
package.json:11
Finding

Unpinned Sensitive Scraper Dependency Without a Project Lockfile

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented behavior promises automatic monitoring, push delivery, trigger handling, and support for custom accounts, but the analyzed implementation reportedly only runs manually with a fixed account list and depends on a pre-existing browser login session. This mismatch can mislead users into exposing authenticated browser state or relying on nonexistent automation controls, creating privacy and operational risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documented behavior promises automatic monitoring, push delivery, trigger handling, and support for custom accounts, but the analyzed implementation reportedly only runs manually with a fixed account list and depends on a pre-existing browser login session. This mismatch can mislead users into exposing authenticated browser state or relying on nonexistent automation controls, creating privacy and operational risk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
node scripts/x-scraper-free.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
node scripts/x-scraper-free.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
1. 编辑 `scripts/x-monitor.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
1. 编辑 `scripts/x-monitor.js`

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a skill that automatically monitors global top AI X/Twitter accounts and generates a structured daily report from those dynamics. However, this function does not call X or a scraper at all; it fabricates random mock tweets and random engagement metrics, so the generated report is not based on real monitored account activity.

Content

No source excerpt is available for this finding.

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
93% confidence
Finding

The YARA hit is justified here because the code invokes browser-cookie extraction, a behavior strongly overlapping with credential-stealing and session-hijacking techniques. In this skill's context, the feature is presented as convenience for scraping, but it still handles highly sensitive authentication material and materially raises the risk profile.

Content

Scanner excerpt · scripts/x-scraper-free.js (reported line 92)May include surrounding context.

js
return [];
  }
}

// 生成日报
async function generateDailyReport() {
  console.log('🚀 开始生成免费版X账号动态日报...');
  const now = new Date();
  const sinceTime = new Date(now.getTime() - 24 * 60 * 60 * 1000);
  
  const accountUpdates = [];
  const topUpdates = [];
  
  // 使用已登录的浏览器会话(自动复用当前Chrome的X登录状态)
  await scraper.useCookiesFromBrowser('chrome');
  
  for (const username of ACCOUNTS) {
    const tweets = await getAccountTweets(username);
    if (tweets.length === 0) {
      accountUpdates.push({
        username,
        type: username.match(/^[A-Z]/) && !username.includes('_') ? '国际机构' : '国际个人',
        tweets: [],
        activity: { score: 0, level: '—', totalEngagement: 0 },
        summary: '无动态'
      });
      continue;
    }
    
    const activity = calculateActivityScore(tweets);
    const summary = tweets[0].text.substring(0, 50) + (tweets[0].text.length > 50 ? '...' : ''

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill advertises automation and references executable scripts plus environment-backed API configuration, but it does not declare any explicit tool scope or permissions boundary. That makes the runtime capabilities less transparent and increases the chance of overbroad access to environment data or unintended tool use when the skill is executed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Broad trigger phrases like 'X日报', 'Twitter监控', and 'AI动态' are common enough to cause accidental invocation in normal conversation. Unintended activation is more concerning here because the skill is described as performing automated scraping, login/session reuse, and scheduled actions, so a false trigger may launch privacy-impacting behavior without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill promotes automatic login reuse, scraping, and scheduled push behavior without prominently warning about privacy, authenticated session exposure, platform-policy implications, or system-side effects. In this context, missing consent and risk disclosure can cause users to unknowingly let the skill operate through an already logged-in browser session or persist recurring tasks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language description states the skill generates a structured daily report in Chinese ('生成结构化日报') and does not indicate that users can select another language or locale. This creates a language policy concern because it appears to impose a specific output language by default without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script sends a bearer token from the environment to Feishu and retrieves account metadata from a remote service without any explicit consent gate, scope validation, or minimization. In an agent-skill context, automatic outbound requests with credentialed headers can expose organizational data or misuse ambient credentials, especially when the skill is advertised as fully automated.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The comments and function header say this code fetches tweets from the past 24 hours, implying real account monitoring. In reality, the implementation logs a message and returns fabricated tweet objects with random IDs, content, and metrics, directly contradicting the documented intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The report title and body are generated in Chinese and the date formatting is explicitly forced to zh-CN. This imposes a specific language/locale choice on all users without offering configuration or opt-in, which matches the language/locale policy-violation category.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code saves a generated report to disk via writeFile, but the only disclosure is a post-write console message indicating where it was saved. There is no prior warning, confirmation, or descriptive comment/docstring telling users that running the script will create a file in the script directory.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script explicitly imports cookies from the user's Chrome browser session to authenticate scraping, which accesses sensitive browser-stored session material beyond what is necessary for a reporting skill. Even if intended only for X/Twitter access, this creates credential/session exposure risk and normalizes a powerful capability commonly associated with session theft or unauthorized account use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill accesses browser session cookies without an explicit warning or consent checkpoint, so a user may unknowingly allow reuse of an authenticated browser session. This can lead to unauthorized actions or exposure of account access if the library mishandles cookies or if the capability is repurposed later.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

文件整体以中文描述技能用途、触发词和输出形式,且未说明是否支持其他语言或允许用户选择语言。对于面向“全球”账号监控的技能,这种默认单一语言约束可能构成未声明的语言/locale 限制。

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
88% confidence
Finding

Using a caret range for @the-convocation/twitter-scraper allows newer minor/patch releases to be installed without review, which creates supply-chain risk if an upstream release becomes compromised or introduces insecure behavior. In a skill that automatically scrapes external content on a schedule, dependency drift increases exposure because the package may run unattended and process untrusted remote data.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
"api": "node scripts/x-monitor.js"
  },
  "dependencies": {
    "@the-convocation/twitter-scraper": "^0.22.1",
    "axios": "^1.6.0"
  },
  "keywords": ["x", "twitter", "scraper", "ai", "daily-report", "monitor"],

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

Using a caret range for axios permits unreviewed version changes at install time, making it harder to know exactly which code is executed and whether known fixes are present. Because this skill performs network operations and may run automatically, supply-chain uncertainty can amplify the chance of exploitable HTTP client issues affecting integrity or data exposure.

Content

Scanner excerpt · package.json (reported line 12)May include surrounding context.

json
},
  "dependencies": {
    "@the-convocation/twitter-scraper": "^0.22.1",
    "axios": "^1.6.0"
  },
  "keywords": ["x", "twitter", "scraper", "ai", "daily-report", "monitor"],
  "author": "",

Unverifiable Dependency: axios has 16 known advisory(ies) (CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The manifest references axios without an exact pinned version, while the package family has multiple known advisories; this means the deployed version may be vulnerable and the manifest does not provide enough assurance otherwise. Given that this skill fetches remote content and may be used in automated monitoring workflows, any affected HTTP client weakness could contribute to SSRF, credential leakage, response tampering, or other network-layer abuse depending on how axios is used elsewhere in the codebase.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all headings, labels, and descriptions exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue when no justification or alternative is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

User-facing output strings and date formatting are fixed to Chinese, including use of the zh-CN locale and Chinese report text. This enforces a specific language/locale without any opt-in or configuration mechanism.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/x-monitor.js:24

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/x-monitor.js:11