X Tweet Monitor

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says, but it requires sensitive X/Twitter session cookies and passes them to an undeclared local tool, so users should review it carefully before installing.

Install only if you trust the `xreach` binary that will run on your machine. Prefer a dedicated or low-risk X/Twitter account, keep AUTH_TOKEN, CT0, and Telegram bot tokens out of source control and logs, rotate them if exposed, and run the monitor only in an environment where you can stop it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The documentation instructs users to provide sensitive credentials including Twitter authentication cookies and Telegram bot credentials, but gives no warning about secure storage, least-privilege handling, or the risk of account compromise if these values are leaked. In a skill that monitors accounts and sends messages over the network, exposed tokens could allow unauthorized access to social-media sessions or bot operations.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal