Back to skill

Security audit

Twitter Operations

Security checks for vulnerabilities and agentic risk

Overview

This Twitter/X automation skill is not clearly malicious, but it requests broad live-account powers without enough scoping or user-control safeguards.

Install only if you intend to grant automation over a real Twitter/X account. Before use, require explicit confirmation for posting, replies, follows, blocks, list changes, and bulk operations; keep credentials in a protected store; disable auto-reply, streaming, scraping, and mass actions unless deliberately configured.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
"Pillow>=10.0.0"
  ],
  "configuration": {
    "credentials_file": "~/.openclaw/twitter_credentials.json",
    "cache_dir": "~/.openclaw/cache/twitter",
    "log_file": "~/.openclaw/logs/twitter.log",
    "archive_dir": "~/.openclaw/archives/twitter"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes very broad phrases like "twitter", "tweet", and especially "social media", which can cause the skill to activate in unrelated contexts. Because this skill can perform account-affecting actions such as posting, following, unfollowing, replying, and bulk operations, accidental invocation could lead to unintended actions against a live Twitter/X account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill advertises sensitive capabilities including mass follow/unfollow/block, auto-reply, bot behavior, multi-account management, scraping, and direct posting without any visible requirement for confirmation, scope limitation, or user-facing safety warnings. In a social-media automation context, these features increase the chance of account abuse, platform-policy violations, reputational damage, and unintended destructive actions if triggered automatically or by ambiguous prompts.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
"Analyze tweet performance and engagement metrics",
    "Follow/unfollow users based on criteria",
    "Like and retweet content",
    "Create and manage Twitter lists",
    "Track follower growth and analytics",
    "Implement Twitter bot functionality",
    "Scrape tweets and user profiles",

Static analysis

No suspicious patterns detected.