Back to skill

Security audit

X (Twitter) 热门账号榜

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent with its stated purpose: it fetches X/Twitter ranking data from RedFox, writes local reports, and can create a user-confirmed daily subscription.

Before installing, be comfortable storing a RedFox API key in your environment and letting the skill create local report files. Confirm any daily subscription intentionally, and check your OpenClaw automation settings if you later want to stop scheduled pushes. Open generated HTML reports with awareness that image export loads a CDN script.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (18)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The subscription feature describes scheduled push delivery but does not prominently warn users that it creates an ongoing action with repeated external message delivery. In agent settings, this can lead to users unknowingly authorizing persistent notifications or recurring outbound actions without clear consent boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README says users can 'Describe your need in natural language — no command syntax to memorize,' but it does not define specific trigger phrases, invocation scope, or negative examples. This ambiguity can cause unintended activation because many everyday requests about rankings, reports, or daily sends could match the skill without clear constraints.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example trigger phrase 'Show me page 2' is highly generic and can overlap with ordinary conversation, making accidental activation or context confusion more likely in an agent environment. If the skill is invoked unintentionally, it could cause undesired data retrieval, stateful pagination changes, or contribute to confused-deputy behavior when multiple skills are available.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README says users can 'directly use natural language to describe your needs' without specifying boundaries, required keywords, or non-triggering cases. For a markdown skill description, this makes invocation conditions ambiguous and increases the chance of unintended activation from ordinary conversation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documents and encourages capabilities that require network access, shell execution, environment-variable access, and local file writes, but it does not declare any explicit tool scope or permissions boundary. This creates a confused-deputy risk where an agent may invoke powerful tools more broadly than the user expects, including using stored API credentials and writing files to the workspace.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description and trigger phrases are entirely Chinese and the document prescribes fixed Chinese response text for certain cases, but it does not mention any user opt-in or alternative language support. Under the stated policy, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language content and keyword mappings are predominantly hard-coded in Chinese, including the update note and category triggers, with no indication that users can choose another language or locale. This can violate language-choice policy when a skill implicitly forces one language without opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The gender mappings include short, high-frequency words like "女" and "男" as standalone keywords. Without contextual constraints, these terms are ambiguous in natural language and can collide with ordinary text, making activation or routing behavior overly broad.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JSON manifest defines activation-like keyword lists for categories, and several entries use extremely broad terms such as "全部", "综合", "所有", and "不限". These common words can appear in ordinary conversation and may cause unintended category matching because the file does not define scope limits or exclusion conditions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file requires the category parameter to use Chinese industry names and explicitly states that internal documentation, configuration, and output must not expose English category values. This is a language/locale constraint presented as mandatory behavior, with no user choice or documented regional justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file instructs the skill to map user natural-language descriptions to industries via fuzzy keyword matching and to fall back broadly to all when no industry is identified. Because the matching is based on common words and the document does not provide negative examples or boundary conditions, the activation scope is ambiguous and may cause unintended category selection.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/fetch_rank.py (reported line 372)May include surrounding context.

python
if args.html:
        script = os.path.join(os.path.dirname(os.path.abspath(__file__)), "generate_report.py")
        subprocess.run([sys.executable, script, "--data", out_path], check=False)


if __name__ == "__main__":

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/generate_report.py (reported line 326)May include surrounding context.

python
try:
        abs_path = os.path.abspath(path)
        if sys.platform == "darwin":
            subprocess.run(["open", abs_path], check=True)
        elif sys.platform.startswith("win"):
            os.startfile(abs_path)  # noqa
        else:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/generate_report.py (reported line 330)May include surrounding context.

python
elif sys.platform.startswith("win"):
            os.startfile(abs_path)  # noqa
        else:
            subprocess.run(["xdg-open", abs_path], check=True)
        print(f"\n✓ HTML 报告已自动打开: {abs_path}", file=sys.stderr)
    except Exception:
        print(f"\n✓ HTML 报告已生成: {os.path.abspath(path)}", file=sys.stderr)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill advertises daily subscription/push behavior but does not clearly warn users about ongoing automated notifications, what parameters are stored, how to cancel, or what data is retained. In a skill that creates recurring push tasks, this can lead to unexpected persistent messaging and unclear handling of user preferences or identifiers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The documentation instructs users to place an API key in environment/config and describes generating local HTML reports, but it does not warn about credential sensitivity, avoiding key disclosure in chat/logs, or the fact that local files will be created automatically. This can lead to accidental secret exposure or surprise file creation in shared or sensitive workspaces.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

该 markdown 文档从标题到字段说明均固定为中文表述,并在 L026 明确要求内部仅使用中文行业名,没有给出用户可选择其他语言/locale 的选项。根据规则,强制特定语言且缺少用户选择或合理限定,属于自然语言层面的语言/locale 策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits HTML with lang="zh-CN" and the surrounding UI text is fixed in Chinese, which enforces a specific language/locale. The policy allows locale constraints when user choice or clear justification is provided, but this file does not offer a language option or document a required regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.