Back to skill

Security audit

推特(X)数据接口

Security checks for vulnerabilities and agentic risk

Overview

This Twitter API skill mostly matches its stated purpose, but it needs review because it sends user queries and an optional paid API key to a third-party service and documents an unsafe command-line key pattern.

Review before installing if you may use sensitive Twitter/X searches or a paid AZT_API_KEY. Prefer using a protected environment secret for AZT_API_KEY, do not paste real keys into prompts or command arguments, and assume tweet IDs, search terms, cursors, and any provided key are sent to coze-js-api.devtool.uk.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/twitter_api.py:178
Finding

API Key Exposure Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/twitter_api.py:178 (unsafe option implementation); SKILL.md:59-60 (unsafe usage guidance)
Vulnerability Type: Sensitive credential exposure through process arguments
Risk Level: Medium

Vulnerable Code

scripts/twitter_api.py:178:

python
parser.add_argument("--azt_api_key", default=None, help="API Key(也可通过环境变量 AZT_API_KEY 设置)")

SKILL.md:59-60:

bash
# 付费版(直接传参)
python3 scripts/twitter_api.py search --keyword "elon musk" --azt_api_key your_key_here

Technical Analysis

The Skill accepts a paid-service API key as a command-line argument and explicitly instructs users to place the secret directly in a shell command. Secrets supplied this way may be exposed through:

  • Shell history files.
  • Process listings and process-monitoring utilities.
  • Endpoint detection, command telemetry, or operating-system audit logs.
  • Terminal session logging and copied command transcripts.
  • Automation logs that record complete command lines.

The script subsequently transmits the key over HTTPS only to the declared third-party API endpoint. That network transmission is required for authenticated use of the declared service and does not, by itself, exceed the Skill's functional privileges. The vulnerability is the optional command-line secret-input channel, not the disclosed HTTPS request.

The documented example places the global option after the subcommand and may not be accepted by the current argparse configuration. Nevertheless, the implementation exposes a functioning command-line credential channel when the global option is placed in an accepted position, such as before the subcommand.

Attack Path

  1. A user invokes the script with a real API key in the command line, for example:

    bash
    python3 scripts/twitter_api.py --azt_api_key REAL_SECRET search --keyword "OpenAI"
    
  2. The complete command is retained in she ...[truncated 1359 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the --azt_api_key command-line option so credentials cannot be supplied through process arguments.
  2. Remove the inline-key command example from SKILL.md.
  3. Retain AZT_API_KEY environment-variable support for non-interactive operation, while documenting that secrets should be injected through a protected runtime secret manager rather than placed in shell startup files or committed configuration.
  4. For interactive use, support a non-echoing prompt with getpass.getpass() when no managed credential is available.
  5. In CI/CD and hosted Agent environments, obtain the key from the platform's credential store and ensure it is masked in logs.
  6. Never print the key or include it in exception messages, request diagnostics, or raw debugging output.
  7. Rotate any production key that has previously been supplied on a command line, and remove affected commands from shell histories and retained logs where feasible.
  8. Apply service-side controls where available, including narrow API scopes, quota limits, expiration, usage monitoring, and rapid revocation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill documents use of environment variables and outbound network requests, but it does not declare any tool scope such as permissions or allowed-tools. That creates a capability/expectation mismatch: an agent may invoke code with network and env access without an explicit policy boundary, increasing the risk of unintended secret access or data exfiltration. In this context, the skill also encourages use of an API key, which makes undeclared env access more sensitive.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the agent to send tweet IDs, keywords, cursors, and related query data to an external third-party endpoint, but it provides no privacy or data-sharing warning. Users may supply sensitive search terms or identifiers without realizing that this information is transmitted off-platform to coze-js-api.devtool.uk, creating confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill tells users to provide an API key via environment variable or directly on the command line, but it gives no credential-handling warning. Passing secrets as direct parameters can expose them through shell history, logs, process listings, chat transcripts, or agent telemetry; combined with the skill's network behavior, this materially increases the chance of credential leakage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.