Back to skill

Security audit

X To Notebook

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent bookmark-sync purpose, but it handles account cookies and private bookmark content with unsafe command construction and under-disclosed persistent data transfer.

Review before installing. Use this only if you are comfortable giving the skill access to exported X session cookies and sending bookmark-derived text, author handles, and source URLs to Google NotebookLM. Avoid running unattended sync until the command construction is fixed, cookie files are stored with restrictive permissions, dependencies are pinned, and the workflow asks for explicit confirmation before uploads.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:91
Finding

Shell Command Injection Through Dynamically Interpolated Notebook and Tweet Content

Content
View full analysis
\"" } ``` For each folder with a resolved notebook, push each bookmark as a text source (X URLs can't be scraped by NotebookLM): ```json { "tool": "exec", "command": "mcporter call notebooklm.source_add notebook_id=\"\" source_type=text text=\"@author: tweet text\n\nSource: https://x.com/author/status/id\"" } ``` ``` ### Technical Analysis The Skill instructs the Agent to construct executable command strings by interpolating dynamic values into shell commands. The affected values include: - A user-supplied notebook title. - Notebook identifiers returned by another tool. - Tweet author names and tweet text retrieved from X. - Tweet URLs generated from externally sourced account and status data. Wrapping these values in double quotes is not sufficient shell escaping. Shell constructs such as `$(command)` and backticks remain active inside double-quoted strings, while embedded quotation marks can terminate the intended argument and introduce additional shell syntax. Consequently, a malicious notebook title or bookmarked tweet could modify the command executed by the Agent if the `exec` facility passes the documented command string to a shell. This issue applies to the agent-directed workflow in `SKILL.md`. The separate `scripts/auto_sync.py` implementation uses an argument-vector subprocess call without `shell=True` and therefore does not expose the same shell injection sink. ### Attack Path 1. An attacker publishes an X post containing shell syntax, such as command substitution or a quotation mark followed by additional shell commands. 2. The victim bookmarks the post. 3. The victim invokes ...[truncated 1242 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/x_login.py:37
Finding

X Session Cookies Are Written Without Enforced Restrictive File Permissions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Security-Sensitive Third-Party Dependencies Are Installed Without Version Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (20)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · CHANGELOG.md (reported line 9)May include surrounding context.

md
- Add `list_folders.py` script
- Add `--folder-id` flag to `fetch_bookmarks.py`
- Add `auto_sync.py` for cron-based unattended sync
- Rewrite SKILL.md workflow for folder-first routing
- Push tweets as text sources instead of URLs (X blocks scraping)
- Strip emojis and `-notebook`/`-bookmarks` suffix from names when matching
- Harden `auto_sync.py`: shell injection prevention, error logging

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · README.md (reported line 26)May include surrounding context.

bash
   # Download and install
   curl -fsSL -o /tmp/google-chrome.deb https://dl.google.com/linux/direct/google-chrome-stable_current_amd64.deb
   sudo dpkg -i /tmp/google-chrome.deb && sudo apt -f install -y
  1. Install and auth NotebookLM MCP:

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description says this skill sends X/Twitter bookmarks to Google NotebookLM and routes them by bookmark folder. The supplied code only authenticates to X using cookies, fetches up to 20 bookmarks via twikit, optionally filters by folder ID, checks a local file of previously pushed bookmark IDs, and prints bookmark data as JSON. There is no code for communicating with NotebookLM, creating/selecting notebooks, or pushing content anywhere. Folder handling exists only as an input to X bookmark retrieval, not as auto-routing into NotebookLM notebooks. Therefore the code’s actual behavior is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose centers on exporting/syncing X bookmarks into Google NotebookLM. However, this code chunk performs a much narrower and different task: it authenticates to X using local cookies and fetches bookmark folder metadata, then outputs that metadata as JSON. There is no NotebookLM interaction, no bookmark retrieval/content transfer, and no routing logic. Accessing X bookmark folders could be a supporting step in a larger workflow, but as supplied, the chunk does not actually implement the declared primary behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill sends X/Twitter bookmarks to Google NotebookLM notebooks, implying bookmark retrieval, routing logic, and integration with NotebookLM. The actual code does none of that. It is a standalone login/credential utility that reads exported browser cookies, converts their format, and writes them to a local credentials file. This is a materially different primary purpose and introduces an undeclared sensitive capability: importing and storing authentication cookies.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README describes convenience behavior but does not prominently warn that the workflow relies on exported X account cookies and transmits bookmark URLs to a Google service. This omission can prevent informed consent and makes accidental exposure of personal reading interests, account-linked data, or sensitive bookmarked links more likely.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 26)May include surrounding context.

bash
   # Download and install
   curl -fsSL -o /tmp/google-chrome.deb https://dl.google.com/linux/direct/google-chrome-stable_current_amd64.deb
   sudo dpkg -i /tmp/google-chrome.deb && sudo apt -f install -y
  1. Install and auth NotebookLM MCP:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad and natural-language generic, which increases the chance the skill activates on ordinary user requests without the user fully understanding that it will access X bookmarks and send bookmark URLs to Google NotebookLM. In a skill that bridges two external services and handles account-linked data, ambiguous invocation raises the risk of unintended data transfer rather than direct code execution.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes unrestricted shell commands via the exec tool and interacts with local files (~/.openclaw/credentials/x-cookies.json) and external services, but it declares no explicit tool scope such as allowed-tools or permissions. That increases the blast radius if the skill is mis-invoked, modified, or if untrusted data later flows into command arguments, because the runtime is not constrained to the minimum necessary capabilities.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Trigger phrases like push my bookmarks and sync bookmarks to notebook are broad enough to match ordinary requests without making clear that the skill will access X bookmarks, local credential material, and send content to Google NotebookLM. Overbroad activation increases the risk of accidental execution and unintended disclosure of private bookmark contents to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description does not prominently warn users that bookmark content, tweet text, author handles, and source URLs will be transmitted from X into Google NotebookLM. This lack of explicit disclosure can lead to uninformed consent and accidental export of sensitive, private, or copyrighted material to a third-party service.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
72% confidence
Finding

The workflow allows creating persistent NotebookLM notebooks and then storing bookmark-derived text in them, creating lasting external state that may outlive the immediate session. Without strong confirmation and visibility, this can cause unintended long-term retention of user data in a third-party system and make cleanup harder if the wrong destination is chosen.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

No notebook matches folder "Random" (4 bookmarks). Pick one:

  1. Notebook Title A
  2. Notebook Title B
  • Create new notebook s. Skip this folder
text

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/auto_sync.py (reported line 41)May include surrounding context.

python
cmd = ["mcporter", "call", f"notebooklm.{tool}"]
    for k, v in kwargs.items():
        cmd.append(f"{k}={shlex.quote(str(v))}")
    result = subprocess.run(cmd, capture_output=True, text=True)
    if result.returncode != 0:
        raise RuntimeError(f"mcporter error: {result.stderr.strip()}")
    return json.loads(result.stdout)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/auto_sync.py (reported line 112)May include surrounding context.

python
"""Mark bookmark IDs as pushed by calling mark_pushed.py."""
    if not ids:
        return
    result = subprocess.run(
        [
            "uv",
            "run",

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code comment states that folder_id=None fetches only unfiled bookmarks, but if the API actually returns all bookmarks, the script may silently sync every bookmark into the notebook mapped from the synthetic Unfiled folder. In this skill context, that can cause unintended cross-folder data disclosure and duplicate or misrouted ingestion of private saved content into NotebookLM.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code initializes an authenticated X client from stored cookies and fetches bookmark data over the network. While the top-level docstring says it fetches bookmarks, there is no explicit runtime disclosure, confirmation, or warning that account data will be accessed and transmitted via the external twikit/X interaction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code loads authentication cookies from a local credentials file and uses them to make a network-backed request to X for bookmark folders. Although the file has a brief module docstring, there is no visible warning, prompt, or user-facing disclosure that the script will access stored account credentials and contact a remote service on the user's behalf.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script persists imported X/Twitter authentication cookies to a predictable local file under ~/.openclaw/credentials, which stores bearer-like session material on disk. Even though this appears to be for legitimate automation, the code does not warn the user about the sensitivity of these cookies, does not set restrictive file permissions explicitly, and does not use a secure credential store, so local compromise, backup leakage, or accidental exposure could allow account takeover.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code initializes the X client with language="en-US", which hard-codes a specific locale. This is a natural-language policy concern because the skill does not offer any user opt-in, configuration path, or documented justification for forcing English (US).

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code hard-codes language="en-US" when creating the client, which imposes a specific locale regardless of user preference. The file does not provide any opt-in, configurability, or explanation that would justify this locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.