Back to skill

Security audit

X (Twitter) 企业家榜单

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent X/Twitter entrepreneur ranking and reporting tool, with disclosed API-key use, network calls, and local report generation, but users should understand the subscription feature depends on external workflow not included here.

Install only if you are comfortable giving the skill a Redfox API key and letting it contact redfox.hk to retrieve ranking and public X/Twitter timeline data. Generated reports are saved locally and may open in your browser; use --no-open if you do not want that. Treat the documented subscription feature as requiring a separate, explicitly confirmed workflow because this package does not include the scheduler/subscription implementation itself.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill claims capabilities such as latest-3-tweet analysis, 30-day topic summaries, subscription delivery, and report download support that are not actually implemented, and it computes 'TOP3' only within the current page rather than the full leaderboard. This is dangerous because users or downstream agents may make business or monitoring decisions based on fabricated, incomplete, or misleading outputs, especially when the skill presents them as authoritative analytics.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises commands that rely on network access, environment secrets, shell execution, and local file generation, but it does not declare any explicit tool scope or permission boundaries. This creates an overbroad execution surface where an agent may invoke sensitive capabilities implicitly, making secret exposure, unintended network calls, or unsafe file writes harder to govern and audit.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation description says to use the skill when users ask about '谁在涨粉', '大佬们在关注什么', or when they need to download reports or subscribe to pushes. These phrases are fairly broad and lack clear scope constraints or negative examples, which could cause unintended activation outside this specific entrepreneur-ranking context.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/fetch_rank.py (reported line 278)May include surrounding context.

python
if args.html:
        script = os.path.join(os.path.dirname(os.path.abspath(__file__)), "generate_report.py")
        subprocess.run([sys.executable, script, "--data", out_path], check=False)


if __name__ == "__main__":

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/generate_report.py (reported line 358)May include surrounding context.

python
try:
        abs_path = os.path.abspath(path)
        if sys.platform == "darwin":
            subprocess.run(["open", abs_path], check=True)
        elif sys.platform.startswith("win"):
            os.startfile(abs_path)  # noqa
        else:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/generate_report.py (reported line 362)May include surrounding context.

python
elif sys.platform.startswith("win"):
            os.startfile(abs_path)  # noqa
        else:
            subprocess.run(["xdg-open", abs_path], check=True)
        print(f"\n✓ HTML 报告已自动打开: {abs_path}", file=sys.stderr)
    except Exception:
        print(f"\n✓ HTML 报告已生成: {os.path.abspath(path)}", file=sys.stderr)

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/api_docs.md:3