Back to skill

Security audit

X402 X Tweet Fetcher

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its paid Xcatcher crawl purpose, but it needs Review because it prints and saves the issued API key and lacks clear confirmation guardrails for paid and external actions.

Install only if you are comfortable sending payment proof, X usernames, and task metadata to xcatcher.top. Before using it, handle PAYMENT-SIGNATURE and XCATCHER_API_KEY as secrets, avoid printing them, avoid keeping buy.json, confirm the cost and destination before any USDC payment, and choose where XLSX results will be saved.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:124
Finding

API Credential Persisted to Disk and Exposed in Terminal Output

Content
View full analysis
Remediation
View remediation
"$BUY_FILE" API_KEY=$(jq -er '.api_key' "$BUY_FILE") export XCATCHER_API_KEY="$API_KEY" rm -f "$BUY_FILE" trap - EXIT echo "XCATCHER_API_KEY exported." ``` - Prefer an operating-system credential store or the agent platform's secret-management facility rather than a long-lived environment variable. - Ensure automation systems mask the API key if it appears in captured output. - Document credential rotation or revocation procedures for suspected exposure. - Unset the environment variable when the workflow is complete: ```bash unset XCATCHER_API_KEY API_KEY ``` ]]>

T08 · Insecure Dependencies

Warning
Location
PUBLISH.md:6
Finding

Unpinned Global Installation of a Third-Party CLI Package

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents an operational integration for buying points, obtaining API access, creating crawl jobs, monitoring them, and fetching results. The actual code does none of those things. It is only a deployment helper script for publishing the skill itself. This is a materially different primary purpose and capability set, so the description does not accurately represent the supplied code chunk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README instructs users to transmit a payment proof and then store and reuse a bearer API key, but it does not explicitly warn that these artifacts are sensitive secrets that can authorize account actions or represent monetary value. In an agent or automation context, this omission increases the chance that payment signatures or API keys will be logged, echoed, persisted in shell history, or exposed to untrusted downstream tools.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill is explicitly user-invocable but lacks activation constraints or guardrails, increasing the chance it is triggered in overly broad contexts. Because the workflow can spend funds, obtain credentials, contact external services, and write files, unconstrained invocation raises the risk of unintended purchases or data collection actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to purchase points with USDC and later save an XLSX file locally, but it does not prominently require explicit user consent for spending money or writing files. In an agent setting, hidden financial actions and filesystem writes are dangerous because they can cause unauthorized charges, unexpected persistence of sensitive data, and privacy issues.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This step sends payment proof and quote data to an external third-party service in order to obtain an API key, which is a sensitive state-changing action rather than a harmless read-only request. In context, this is more dangerous because it follows an on-chain payment flow; if triggered without strong consent or validation, it could finalize a purchase and expose payment-linked metadata to the service.

Content

Scanner excerpt · SKILL.md (reported line 151)May include surrounding context.

bash
BASE="https://xcatcher.top"

curl -sS -X POST "$BASE/api/v1/x402/buy_points" \
  -H "Content-Type: application/json" \
  -H "PAYMENT-SIGNATURE: $PAYMENT_SIGNATURE_B64" \
  -d "$(jq -nc --arg q "$QUOTE_ID" '{quote_id:$q}')" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This request transmits user-supplied targets and an authorization token to an external service to create a crawl task. While expected for the skill's purpose, it is still a real external transmission risk because it shares potentially sensitive target lists and can trigger paid or regulated data collection operations.

Content

Scanner excerpt · SKILL.md (reported line 211)May include surrounding context.

md
)"
echo

curl -sS -X POST "$BASE/api/v1/tasks" \
  -H "Authorization: Bearer $XCATCHER_API_KEY" \
  -H "Content-Type: application/json" \
  -d "$(jq -nc --arg mode "$MODE" --arg idem "$IDEM" --argjson users "$USERS_JSON" \

Static analysis

No suspicious patterns detected.