Back to skill

Security audit

Twitter Research

Security checks for vulnerabilities and agentic risk

Overview

This Twitter/X research skill is mostly purpose-aligned, but it asks the agent to install and run unpinned browser automation against a real logged-in Chrome session and to fall back to third-party tweet APIs.

Review before installing. This skill can be useful for Twitter/X research, but only use it if you are comfortable letting it install browser automation software, control a real logged-in Chrome session, and send public tweet URLs or IDs to fxtwitter/vxtwitter as fallbacks. A safer setup would preinstall pinned tooling, use a dedicated browser profile, and ask before third-party API fallback.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:38
Finding

Automatic Installation of Unpinned Third-Party Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 38-43
Vulnerability Type: Unpinned third-party package and runtime component installation
Risk Level: Medium

Complete Code Snippet

bash
if ! which browser-use &>/dev/null; then
  echo "INSTALLING browser-use..."
  uv tool install browser-use && browser-use install
fi
# 验证
which browser-use &>/dev/null && echo "READY" || echo "INSTALL_FAILED"

Technical Analysis

The Skill instructs the agent to install browser-use automatically when it is unavailable. The command does not specify an exact package version, dependency lockfile, package hash, signature, or other integrity constraint. Consequently, the package and its transitive dependencies are resolved from mutable third-party supply-chain content at execution time.

After installation, the newly obtained executable immediately runs browser-use install, which may download and install additional browser components. Those artifacts are likewise not pinned or integrity-verified in the documented workflow. Because package installation and execution occur during ordinary Skill use, the effective code executed by the agent can differ from the code reviewed during this audit.

This finding concerns unsafe dependency acquisition. The audited file does not establish that the current browser-use package is malicious.

Attack Path

  1. A user invokes the Twitter/X research Skill on a system where browser-use is not installed.
  2. The availability check fails.
  3. The agent executes uv tool install browser-use without selecting an audited exact version or verifying artifact integrity.
  4. A compromised package release, registry account, transitive dependency, package source, or distribution artifact supplies attacker-controlled code.
  5. The installed executable is immediately invoked through browser-use install.
  6. Attacker-controlled installation logic executes with the operating-sy ...[truncated 976 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic dependency installation from normal Skill execution and require explicit, informed user approval before installing software.
  2. Pin browser-use to a reviewed exact version rather than resolving the latest available release.
  3. Maintain and enforce a lockfile for all transitive dependencies.
  4. Verify downloaded package and browser-component hashes or trusted signatures before execution.
  5. Use an approved package index or internally mirrored artifact repository with provenance controls.
  6. Install dependencies during a separate, controlled provisioning stage rather than immediately before handling an authenticated browser session.
  7. Run browser automation in a sandboxed, least-privilege environment with restricted filesystem and network access.
  8. Use a dedicated browser profile containing only the minimum authentication state needed for the task.
  9. Document the expected component versions and periodically review them for known vulnerabilities before controlled upgrades.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill goes beyond simple Twitter research by instructing the agent to install and run external browser automation software via shell commands. This expands the execution surface, enables persistent tool changes in the environment, and creates supply-chain and abuse risks unrelated to the user’s immediate request.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The fallback path sends tweet identifiers and query-derived browsing targets to unaffiliated third-party APIs (fxtwitter/vxtwitter), which is outside the narrowly scoped Twitter/X research function. This creates unnecessary data egress and trust-dependency on external services that may log requests, return manipulated content, or change behavior unexpectedly.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This command transmits tweet-derived data to api.fxtwitter.com, a third-party external service, without any trust boundary controls or user consent. Even if the content is public, the request leaks user research targets and relies on an unvetted service for data integrity and availability.

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
# 2. 从搜索结果提取推文 URL,用 fxtwitter API 获取详情
#    URL 格式: https://x.com/{username}/status/{tweet_id}
curl -s "https://api.fxtwitter.com/{username}/status/{tweet_id}"

# 3. fxtwitter 不可用时尝试 vxtwitter
curl -s "https://api.vxtwitter.com/{username}/status/{tweet_id}"

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This fallback sends the same research context to api.vxtwitter.com, introducing the same external transmission and integrity risks as the primary fallback. The extra redundancy also increases the number of third parties that may observe or influence the agent’s outputs.

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

curl -s "https://api.fxtwitter.com/{username}/status/{tweet_id}"

3. fxtwitter 不可用时尝试 vxtwitter

curl -s "https://api.vxtwitter.com/{username}/status/{tweet_id}"

text

### Step 5: 清理

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instructions require '中英文双搜' for the same topic, which imposes a specific language behavior regardless of the user's preference. Under the policy, language or locale constraints should either be optional or clearly justified; here no user choice or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.