T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/x-scraper-free.js:91- Finding
Authenticated Browser Session Exposed to a Third-Party Scraper
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly aims to generate X/Twitter AI account reports, but it reuses Chrome login cookies through a third-party scraper and overstates automation and data authenticity.
Review this before installing. Use only a dedicated browser profile or test X account if you run the free scraper, avoid exposing your primary Chrome session, and do not rely on the official API mode for real reports until the mock-data path is replaced. Pin dependencies and move credentials to environment or secret storage before operational use.
scripts/x-scraper-free.js:91Authenticated Browser Session Exposed to a Third-Party Scraper
scripts/x-monitor.js:9Credential-Like X API Material Hard-Coded in Source Code
scripts/x-monitor.js:49Official API Mode Produces Randomized Mock Data as a Daily Report
package.json:11Unpinned Sensitive Scraper Dependency Without a Project Lockfile
The documented behavior promises automatic monitoring, push delivery, trigger handling, and support for custom accounts, but the analyzed implementation reportedly only runs manually with a fixed account list and depends on a pre-existing browser login session. This mismatch can mislead users into exposing authenticated browser state or relying on nonexistent automation controls, creating privacy and operational risk.
The documented behavior promises automatic monitoring, push delivery, trigger handling, and support for custom accounts, but the analyzed implementation reportedly only runs manually with a fixed account list and depends on a pre-existing browser login session. This mismatch can mislead users into exposing authenticated browser state or relying on nonexistent automation controls, creating privacy and operational risk.
Referenced artifact was not completely inspected
node scripts/x-scraper-free.js
Referenced artifact was not completely inspected
node scripts/x-scraper-free.js
Referenced artifact was not completely inspected
1. 编辑 `scripts/x-monitor.js`
Referenced artifact was not completely inspected
1. 编辑 `scripts/x-monitor.js`
The manifest describes a skill that automatically monitors global top AI X/Twitter accounts and generates a structured daily report from those dynamics. However, this function does not call X or a scraper at all; it fabricates random mock tweets and random engagement metrics, so the generated report is not based on real monitored account activity.
The YARA hit is justified here because the code invokes browser-cookie extraction, a behavior strongly overlapping with credential-stealing and session-hijacking techniques. In this skill's context, the feature is presented as convenience for scraping, but it still handles highly sensitive authentication material and materially raises the risk profile.
return [];
}
}
// 生成日报
async function generateDailyReport() {
console.log('🚀 开始生成免费版X账号动态日报...');
const now = new Date();
const sinceTime = new Date(now.getTime() - 24 * 60 * 60 * 1000);
const accountUpdates = [];
const topUpdates = [];
// 使用已登录的浏览器会话(自动复用当前Chrome的X登录状态)
await scraper.useCookiesFromBrowser('chrome');
for (const username of ACCOUNTS) {
const tweets = await getAccountTweets(username);
if (tweets.length === 0) {
accountUpdates.push({
username,
type: username.match(/^[A-Z]/) && !username.includes('_') ? '国际机构' : '国际个人',
tweets: [],
activity: { score: 0, level: '—', totalEngagement: 0 },
summary: '无动态'
});
continue;
}
const activity = calculateActivityScore(tweets);
const summary = tweets[0].text.substring(0, 50) + (tweets[0].text.length > 50 ? '...' : ''
The skill advertises automation and references executable scripts plus environment-backed API configuration, but it does not declare any explicit tool scope or permissions boundary. That makes the runtime capabilities less transparent and increases the chance of overbroad access to environment data or unintended tool use when the skill is executed.
Broad trigger phrases like 'X日报', 'Twitter监控', and 'AI动态' are common enough to cause accidental invocation in normal conversation. Unintended activation is more concerning here because the skill is described as performing automated scraping, login/session reuse, and scheduled actions, so a false trigger may launch privacy-impacting behavior without clear user intent.
The skill promotes automatic login reuse, scraping, and scheduled push behavior without prominently warning about privacy, authenticated session exposure, platform-policy implications, or system-side effects. In this context, missing consent and risk disclosure can cause users to unknowingly let the skill operate through an already logged-in browser session or persist recurring tasks.
The natural-language description states the skill generates a structured daily report in Chinese ('生成结构化日报') and does not indicate that users can select another language or locale. This creates a language policy concern because it appears to impose a specific output language by default without documented opt-in or justification.
The script sends a bearer token from the environment to Feishu and retrieves account metadata from a remote service without any explicit consent gate, scope validation, or minimization. In an agent-skill context, automatic outbound requests with credentialed headers can expose organizational data or misuse ambient credentials, especially when the skill is advertised as fully automated.
The comments and function header say this code fetches tweets from the past 24 hours, implying real account monitoring. In reality, the implementation logs a message and returns fabricated tweet objects with random IDs, content, and metrics, directly contradicting the documented intent.
The report title and body are generated in Chinese and the date formatting is explicitly forced to zh-CN. This imposes a specific language/locale choice on all users without offering configuration or opt-in, which matches the language/locale policy-violation category.
The code saves a generated report to disk via writeFile, but the only disclosure is a post-write console message indicating where it was saved. There is no prior warning, confirmation, or descriptive comment/docstring telling users that running the script will create a file in the script directory.
The script explicitly imports cookies from the user's Chrome browser session to authenticate scraping, which accesses sensitive browser-stored session material beyond what is necessary for a reporting skill. Even if intended only for X/Twitter access, this creates credential/session exposure risk and normalizes a powerful capability commonly associated with session theft or unauthorized account use.
The skill accesses browser session cookies without an explicit warning or consent checkpoint, so a user may unknowingly allow reuse of an authenticated browser session. This can lead to unauthorized actions or exposure of account access if the library mishandles cookies or if the capability is repurposed later.
文件整体以中文描述技能用途、触发词和输出形式,且未说明是否支持其他语言或允许用户选择语言。对于面向“全球”账号监控的技能,这种默认单一语言约束可能构成未声明的语言/locale 限制。
Using a caret range for @the-convocation/twitter-scraper allows newer minor/patch releases to be installed without review, which creates supply-chain risk if an upstream release becomes compromised or introduces insecure behavior. In a skill that automatically scrapes external content on a schedule, dependency drift increases exposure because the package may run unattended and process untrusted remote data.
"api": "node scripts/x-monitor.js"
},
"dependencies": {
"@the-convocation/twitter-scraper": "^0.22.1",
"axios": "^1.6.0"
},
"keywords": ["x", "twitter", "scraper", "ai", "daily-report", "monitor"],
Using a caret range for axios permits unreviewed version changes at install time, making it harder to know exactly which code is executed and whether known fixes are present. Because this skill performs network operations and may run automatically, supply-chain uncertainty can amplify the chance of exploitable HTTP client issues affecting integrity or data exposure.
},
"dependencies": {
"@the-convocation/twitter-scraper": "^0.22.1",
"axios": "^1.6.0"
},
"keywords": ["x", "twitter", "scraper", "ai", "daily-report", "monitor"],
"author": "",
The manifest references axios without an exact pinned version, while the package family has multiple known advisories; this means the deployed version may be vulnerable and the manifest does not provide enough assurance otherwise. Given that this skill fetches remote content and may be used in automated monitoring workflows, any affected HTTP client weakness could contribute to SSRF, credential leakage, response tampering, or other network-layer abuse depending on how axios is used elsewhere in the codebase.
This markdown file presents all headings, labels, and descriptions exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue when no justification or alternative is provided.
User-facing output strings and date formatting are fixed to Chinese, including use of the zh-CN locale and Chinese report text. This enforces a specific language/locale without any opt-in or configuration mechanism.
Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal