Back to skill

Security audit

X Articles

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly coherent for drafting and publishing X Articles, but it gives agents live browser-session publishing authority without a clear final human approval requirement.

Install only if you are comfortable giving an agent browser automation access to a logged-in X account. Review the article yourself before any publish command, prefer a dedicated browser profile or test account, avoid global unpinned installs where possible, and keep backups of source articles before using the formatter.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/publish-article.sh:52
Finding

Predictable Temporary File Allows Symlink-Based File Clobbering

Content
View full analysis
/tmp/x-article-snapshot.txt 2>&1 if ! grep -qi "contenteditable\|article\|editor" /tmp/x-article-snapshot.txt; then echo "Warning: Editor may not have loaded. Check browser." fi ``` ### Technical Analysis The script writes browser snapshot data to the fixed path `/tmp/x-article-snapshot.txt`. It does not securely create the file, verify its ownership, reject symbolic links, restrict its permissions, or remove it after use. On systems where symbolic-link protections do not block the operation, another local user can create this predictable path as a symbolic link to a file writable by the victim. Shell redirection follows the link and truncates the target before `agent-browser` runs. An attacker may also pre-create a permissively readable regular file at the expected path. If the victim can open that file for writing, the resulting browser snapshot may remain accessible to the attacker. Such snapshots can contain information from the authenticated X page. ### Attack Path 1. A local attacker predicts the fixed path `/tmp/x-article-snapshot.txt`. 2. The attacker creates that path as a symbolic link to a target writable by the intended victim, or creates an attacker-readable regular file at that location. 3. The victim executes `publish-article.sh`. 4. The shell opens the predictable path using output redirection. 5. In the symbolic-link case, the linked target is truncated and overwritten with browser output. 6. In the regular-file case, the attacker may read the snapshot after the script writes authenticated-page information to it. 7. The script does not clean up the temporary artifact. The feasibility of the symbolic-link variant depends on ...[truncated 541 chars]
Remediation
View remediation
"$SNAPSHOT_FILE" 2>&1 if ! grep -qi "contenteditable\|article\|editor" "$SNAPSHOT_FILE"; then echo "Warning: Editor may not have loaded. Check browser." fi ``` ]]>

T08 · Insecure Dependencies

Warning
Location
scripts/publish-article.sh:35
Finding

Unpinned Global Installation of a Browser-Automation Dependency

Content
View full analysis
/dev/null; then echo "Error: agent-browser not found. Install with: npm install -g agent-browser" exit 1 fi ``` Related metadata in `skill.json` also declares the dependency without a version: ```json "dependencies": { "cli": ["agent-browser"], "optional": ["pbcopy"] } ``` ### Technical Analysis The installation instruction resolves the current package associated with the mutable npm package name `agent-browser`. It does not specify an audited version, lockfile, integrity hash, trusted publisher identity, or verified distribution source. Global npm installation can execute package lifecycle scripts and places executable content into a global command path. A compromised future release, registry account, or dependency in the package's transitive dependency tree could therefore execute code with the installing user's privileges. This is particularly sensitive because the installed tool is subsequently given access to a Chrome DevTools Protocol endpoint connected to a browser logged into X. ### Attack Path 1. The user runs the script without `agent-browser` installed. 2. The script instructs the user to execute `npm install -g agent-browser`. 3. npm resolves the latest package release and its transitive dependencies from the configured registry. 4. Package installation scripts execute and global binaries are installed. 5. If the resolved package or a transitive dependency has been compromised, attacker-controlled code runs with the installing user's privileges. 6. When the publishing script is later used, the compromised executable receives access to the configured CDP endpoint and authenticated browser session. This attack path requires compromise or malicio ...[truncated 676 chars]
Remediation
View remediation
``` The placeholder must be replaced with a version that the project maintainers have actually audited. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
scripts/format-for-x.sh:12
Finding

Formatter Can Truncate Its Own Input File

Content
View full analysis
"$OUTPUT" ``` ### Technical Analysis Shell output redirection opens an ...[truncated 1781 chars]
Remediation
View remediation
&2 exit 1 fi if [ -e "$OUTPUT" ] && [ "$INPUT" -ef "$OUTPUT" ]; then echo "Error: Input and output refer to the same file." >&2 exit 1 fi TEMP_OUTPUT="$(mktemp "$OUTPUT_DIR/.${OUTPUT_BASE}.XXXXXX")" trap 'rm -f -- "$TEMP_OUTPUT"' EXIT # Send the completed transformation pipeline to "$TEMP_OUTPUT". # Move it only after every pipeline stage succeeds. mv -- "$TEMP_OUTPUT" "$OUTPUT" trap - EXIT ``` The script should also enable `set -o pipefail` so a failure in an earlier pipeline stage cannot be masked by a successful later command. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description promises an AI-powered system for publishing viral X/Twitter articles, including browser automation and engagement-oriented content patterns. The supplied code does not perform any publishing, automation, AI interaction, or social-media-specific workflow beyond text formatting conventions. Its actual purpose is narrowly limited to converting markdown into a plain-text format suitable for X Articles editing. That is materially different from the declared end-to-end publishing and AI content functionality, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The browser automation instructions assume an already authenticated X session and proceed to operate against that account with no guardrails or warning about account-impacting actions. In an agent-enabled environment, this lowers the barrier to unauthorized or accidental use of a privileged browser session for posting, media upload, or other account actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill provides direct steps to click Publish and confirm the action in a logged-in X session without any required verification, dry-run step, or user confirmation checkpoint. In an agent context, this can cause unintended public posting, reputational harm, or policy-violating content to be published irreversibly before a human reviews it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest explicitly advertises browser automation and publishing to X/Twitter, which are account-impacting actions, but it provides no user-facing warning, consent language, or indication that content may be posted on the user's behalf. In an agent ecosystem, this increases the risk of users invoking the skill without appreciating that it can perform live posting actions, potentially causing unintended publication, reputational harm, or account misuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.