Back to skill

Security audit

OpenTweet X Poster

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed OpenTweet integration for managing X posts, media, analytics, articles, evergreen queues, and human-approved DM outreach through the user's API key.

Install only if you are comfortable giving OpenTweet API access to manage the connected X account. Review posts, articles, evergreen settings, and DM leads before approving actions, and be aware that uploaded/generated media, drafts, schedules, analytics, and campaign data may be stored or processed by OpenTweet.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill is user-invocable and exposes a very broad set of high-impact actions ('post', 'schedule', 'publish', DM outreach, analytics, repurpose) without narrowly defined trigger boundaries or scoping. In an agent environment, vague activation language increases the chance the skill is invoked for unintended requests, causing external side effects such as posting content or initiating outreach without sufficiently explicit user intent.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill sends user-authored content, connected-account metadata, analytics, uploaded media, and potentially lead-discovery/DM campaign data to the external OpenTweet service and related processors, but the introduction does not present a clear upfront privacy and third-party data-sharing warning. Users may unknowingly expose sensitive drafts, account information, contact targets, or media to external systems, including AI generation features and outreach workflows.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.