Back to skill

Security audit

frigatebird

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned for controlling X from a CLI, but it handles sensitive X session credentials, can perform live account actions, and runs an unpinned npm package without enough safety guidance.

Install only if you are comfortable giving a CLI access to your X session and allowing it to perform live account actions. Prefer a pinned, reviewed package version, run it in a least-privilege environment, protect cookies and browser profiles as account credentials, and require explicit confirmation before posting, following, or changing lists.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned Third-Party npm Package Installation and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20–21
Vulnerability Type: Unpinned and immediately executable third-party dependency
Risk Level: Medium

Complete Code Snippet:

markdown
- Global install: `npm install -g frigatebird`
- Local use: `npx frigatebird <command>`

Technical Analysis

The skill instructs users or agents to install and execute the frigatebird npm package without specifying a reviewed version, integrity hash, lockfile, or verified source repository. Both commands therefore resolve mutable package content from the configured npm registry.

In particular, npx frigatebird <command> may download and immediately execute the package. npm installation can also run package lifecycle scripts. Consequently, a compromised account, malicious replacement release, dependency compromise, registry substitution, or unexpectedly changed package version could cause attacker-controlled code to run without any corresponding change to the reviewed skill file.

The package is intended to interact with authenticated X sessions and accepts authentication tokens, cookies, cookie sources, and browser-profile options. Although the reviewed file contains no evidence that the current package is malicious, the unpinned execution guidance creates a supply-chain exposure with elevated consequences.

Attack Path

  1. An attacker compromises the npm package, one of its transitive dependencies, its publisher account, or the registry path used by the victim.
  2. The attacker publishes a malicious version under the package name resolved by the unpinned commands.
  3. A user or agent follows the skill instructions and runs npm install -g frigatebird or npx frigatebird <command>.
  4. npm retrieves the attacker-controlled release because no trusted version or integrity value is required.
  5. Malicious package code or lifecycle scripts execute with the permissions of the invoking ac ...[truncated 962 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the package to a specifically reviewed version, for example frigatebird@X.Y.Z, instead of resolving the latest release.
  2. Prefer a project-local installation governed by a committed lockfile rather than a mutable global installation.
  3. Verify package provenance, publisher identity, repository ownership, release signatures or attestations, and npm integrity metadata before use.
  4. Use deterministic installation such as npm ci with a reviewed lockfile where the surrounding project structure permits it.
  5. Avoid direct npx execution of an unpinned package. If npx remains necessary, specify the exact reviewed version and configure it to avoid silently resolving unexpected packages.
  6. Disable npm lifecycle scripts during installation where compatible with the package, or independently review every required lifecycle script before permitting execution.
  7. Run the CLI with least privilege in an isolated environment and expose only the specific browser profile, cookies, and credentials required for the requested operation.
  8. Document the authoritative source repository and a package verification procedure so users can validate that the installed artifact corresponds to the reviewed implementation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
t`, `post`, `reply`, `article`, `like`, `retweet`, `follow`, `unfollow`, `unbookmark`
- Read/timelines: `read`, `replies`, `thread`, `search`, `mentions`, `user-tweets`, `home`, `bookmarks`, `likes`, `list-timeline`, `news`, `about`
- Identity/health: `check`, `whoami`, `query-ids`, `help`
- List automation: `add`, `remove`, `batch`, `lists`, `list`, `refresh`

## Options That Matter Most

- Auth/cookies: `--auth-token`, `--ct0`, `--cookie-source`, `--chrome-profile`, `--firefox-profile`
- Determinism/testing: `--base-url`, `--plain`, `--no-color`
- Pagination: `-n`, `--all`, `--max-pages`, `--cursor`, `--delay`
- Output: `--json`, `--json-full`
- Media posting: `--media`, `--alt`

## Live E2E Notes

- Standard live mutation e2e does not run premium-feature checks by default.
- Premium-feature e2e opt-in:
  - `npm run test:e2e:live -- --list-name <name> --enable-premium-features-e2e --article-cookie-source chrome --article-expected-handle-prefix <prefix>`

## Caveats

- This tool depen

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill promotes browser-session-cookie-based authentication and later references cookie and profile options without any security or privacy warning about handling account session credentials. Exposing or mishandling these tokens could allow full account takeover or unauthorized use of the user's X session.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The skill instructs users to run npx frigatebird, which fetches and executes the latest package version at runtime without pinning or integrity controls. If the package is compromised or a malicious update is published, users could execute attacker-controlled code immediately from the skill workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documents live mutation commands such as posting, replying, following, and list automation without clearly warning that these actions will modify the user's X account and lists. This increases the risk of accidental harmful actions, especially when an agent or script invokes these commands on the user's behalf.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.