Back to skill

Security audit

Twitter Monitor By Longge

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims, but it uses high-value Twitter session cookies in a way that can expose them to the local process environment and an unspecified external tool.

Review this before installing. Use only a disposable or low-risk X/Twitter session if possible, understand that Twitter cookies can grant account access, and avoid running it on shared or heavily monitored hosts because the cookies are passed to xreach as process arguments. Also verify the source and version of xreach before use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
twitter_monitor.py:15
Finding

Twitter Session Credentials Exposed Through Process Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: twitter_monitor.py, line 15
Vulnerability Type: Sensitive credential exposure through process arguments
Risk Level: Medium

python
r = subprocess.run(["xreach","tweets",f"@{U}","-n","10","--auth-token",A,"--ct0",C,"--json"],capture_output=True,text=True,timeout=30)

Technical Analysis

The application passes the AUTH_TOKEN and CT0 Twitter session credentials directly to the xreach executable as command-line arguments. Although using an argument list rather than a shell command prevents shell metacharacter injection, it does not preserve the confidentiality of those arguments.

Depending on the operating system configuration and execution environment, process arguments may be visible through process inspection interfaces, monitoring agents, diagnostic tooling, audit logs, crash reports, or orchestration telemetry. Any party able to observe the xreach process while it is running could therefore obtain reusable Twitter session credentials.

Attack Path

  1. An operator configures valid Twitter AUTH_TOKEN and CT0 environment variables and starts the monitor.
  2. The application launches xreach, placing both credential values in its process argument vector.
  3. A local user, privileged monitoring agent, process-inspection service, or command-line logging facility observes or records the arguments before the process exits.
  4. The observer extracts the exposed session credentials.
  5. The credentials are replayed against Twitter/X, subject to their validity and the permissions associated with the authenticated session.

Impact Assessment

Successful exploitation may allow an attacker to impersonate the affected Twitter/X session and perform actions permitted by those credentials. The precise scope depends on Twitter/X session controls, account permissions, credential validity, and additional authentication requirements.

This issue does not itself provide operating-system privilege esca ...[truncated 141 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not pass session credentials through command-line arguments.
  • Use a credential-delivery mechanism supported by xreach that does not expose values in the process argument vector, such as inherited environment variables or standard input.
  • If xreach only supports a configuration file, create it with restrictive owner-only permissions, avoid shared temporary directories, and delete it reliably after use.
  • Restrict host access and configure process-monitoring, logging, and orchestration systems not to collect sensitive command arguments.
  • Rotate the affected AUTH_TOKEN and CT0 values if there is any possibility that process arguments have already been logged or observed.
  • Document and pin the trusted source and version of the external xreach executable to reduce supply-chain and behavioral uncertainty.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares no explicit tool scope or permission boundaries even though its documented behavior requires access to environment variables, network services, and shell execution. Without a declared least-privilege scope, an agent platform may grant broader capabilities than necessary, increasing the chance of secret exposure or unintended outbound network actions if the skill or its dependencies are modified or abused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill reads multiple sensitive credentials from environment variables, including Twitter auth cookies and Telegram bot credentials, without any in-code disclosure, consent flow, or guidance on handling them securely. In an agent-skill context, this can lead users to provide high-value secrets without understanding that the skill depends on session tokens that could enable account access if mishandled.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · twitter_monitor.py (reported line 15)May include surrounding context.

python
def get():
    if not A or not C: return None
    r = subprocess.run(["xreach","tweets",f"@{U}","-n","10","--auth-token",A,"--ct0",C,"--json"],capture_output=True,text=True,timeout=30)
    try: return json.loads(r.stdout).get("items")
    except: return None

Tainted flow: 'A' from os.getenv (line 6, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · twitter_monitor.py (reported line 15)May include surrounding context.

python
def get():
    if not A or not C: return None
    r = subprocess.run(["xreach","tweets",f"@{U}","-n","10","--auth-token",A,"--ct0",C,"--json"],capture_output=True,text=True,timeout=30)
    try: return json.loads(r.stdout).get("items")
    except: return None

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code forwards tweet-derived content to Telegram without any explicit disclosure in the implementation that monitored content will be transmitted to a third-party messaging service. In this skill's context, exfiltrating monitored account content and metadata to Telegram is core functionality, but it still creates a privacy and data-sharing risk if users are not clearly informed.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · twitter_monitor.py (reported line 23)May include surrounding context.

python
if not TB or not TC: return
    import aiohttp
    async with aiohttp.ClientSession() as s:
        await s.post(f"https://api.telegram.org/bot{TB}/sendMessage",json={"chat_id":TC,"text":m})

async def main():
    log(f"Started: @{U}")

Static analysis

No suspicious patterns detected.