Back to skill

Security audit

Grok Twitter Search

Security checks for vulnerabilities and agentic risk

Overview

This package looks like a personal OpenClaw workspace bundled with several unrelated high-privilege skills, so it needs review before installation.

Install only in an isolated OpenClaw profile after removing unrelated workspace memory/persona files, pinning install versions, avoiding curl-to-shell setup, and using dedicated low-value API keys and a low-value blockchain wallet. Do not use the Four.Meme trading skill with a primary wallet, and review any heartbeat or memory automation before enabling it.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
skills/grok-twitter-search/scripts/setup_interactive.py:35
Finding

Remote Installer Is Downloaded and Piped Directly to a Shell

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/grok-twitter-search/scripts/setup_interactive.py:245
Finding

Setup Wizard Prints and Stores the Complete Grok API Key in Plaintext

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/grok-twitter-search/scripts/search_twitter.py:24
Finding

Custom API Base Can Redirect the Grok Bearer Credential to an Arbitrary Server

Content
View full analysis
dict: """ 调用 Grok x_search,要求返回结构化 JSON """ url = f"{api_base.rstrip('/')}/responses" headers = { "Authorization": f"Bearer {api_key}", "Content-Type": "application/json" } ``` The destination is directly controllable through a command-line option: ```python parser = argparse.ArgumentParser(description="Grok Twitter Search") parser.add_argument("--query", required=True, help="搜索查询") parser.add_argument("--api-key", help="Grok API Key") parser.add_argument("--api-base", default="https://api.x.ai/v1") parser.add_argument("--max-results", type=int, default=10) parser.add_argument("--proxy", help="SOCKS5 代理") args = parser.parse_args() api_key = args.api_key or os.environ.get("GROK_API_KEY") if not api_key: print(json.dumps({"status": "error", "message": "缺少 GROK_API_KEY"})) sys.exit(1) result = search_twitter( args.query, api_key, args.api_base, args.max_results, proxy ) ``` ### Technical Analysis The script appends `/responses` to an unrestricted `--api-base` value and attaches the production bearer credential to the resulting request. It does not validate that: - The scheme is HTTPS. - The hostname is `api.x.ai`. - The destination is not localhost, a private network, or an attacker-controlled host. - A custom endpoint is authorized to receive the same credential. This creates a direct credential-redirection primitive. An attacker does not need code execution if they can influence the generated command, documentation, copied invocation, or agent arguments. ### Att ...[truncated 894 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
skills/four-meme-ai/SKILL.md:90
Finding

Unpinned Global Package Is Executed with Access to a Wallet Private Key

Content
View full analysis
[args]`. ``` The installed package is subsequently given access to the private key: ```markdown ### PRIVATE_KEY and BSC_RPC_URL **When using OpenClaw** This skill declares `requires.env: ["PRIVATE_KEY"]` and `primaryEnv: "PRIVATE_KEY"` in metadata; OpenClaw injects them only when an agent runs with **this skill enabled**. **Required steps:** 1. **Configure private key**: In the Skill management page, set the four-meme-ai skill’s **apiKey** (corresponds to `primaryEnv: "PRIVATE_KEY"`), or set `PRIVATE_KEY` under `skills.entries["four-meme-ai"].env` in `~/.openclaw/openclaw.json`. 2. **Enable this skill**: In the agent or session, ensure the **four-meme-ai** skill is **enabled**. ``` The metadata confirms the privilege: ```yaml metadata: {"author":"Four.meme AI Skill","version":"1.0.0","openclaw":{"requires":{"env":["PRIVATE_KEY"]},"primaryEnv":"PRIVATE_KEY","optionalEnv":["BSC_RPC_URL"]}} ``` ### Technical Analysis `@latest` is a mutable npm distribution tag. The code installed in the future may differ from the local TypeScript files included in this audited artifact. Global installation broadens the installation scope and may execute npm lifecycle scripts. Once installed, the CLI is invoked while a raw wallet private key is available in the process environment. The reviewed bundled Four.Meme scripts did not directly upload the private key: they derive an account locally, sign authentication messages, and submi ...[truncated 1268 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
opennews-mcp/src/opennews_mcp/api_client.py:106
Finding

OpenNews WebSocket Authentication Token Is Embedded in the URL Query String

Content
View full analysis
str: self._request_id += 1 return f"req_{self._request_id}_{int(time.time())}" async def connect(self): import websockets self._ws = await websockets.connect(self.wss_url) ``` ### Technical Analysis The WebSocket credential is placed directly in the connection URL. Query strings are commonly recorded by reverse proxies, access logs, tracing systems, diagnostic tools, exception reports, and connection telemetry. This gives the token a larger accidental-disclosure surface than an authentication header. The REST client in the same file uses an `Authorization` header, demonstrating a safer authentication pattern. Real-time news subscription requires authentication, but placing a long-lived bearer token in the URL is not the minimum-risk implementation. Additionally, the configured WebSocket base URL can be overridden through `OPENNEWS_WSS_URL`. If an attacker can modify the process environment or configuration, the token will be appended to the substituted destination. Such configuration control may already represent local access, but it increases the consequences of configuration manipulation. ### Attack Path 1. The user configures a valid `OPENNEWS_TOKEN`. 2. `NewsWSClient` constructs a URL ending in `?token=`. 3. A reverse proxy, WebSocket gateway, monitoring agent, or diagnostic logger records the full URL. 4. An attacker or unauthorized operator obtains access to those logs. 5. The attacker extracts and re ...[truncated 538 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (195)

Known Vulnerable Dependency: protobufjs==6.11.4 — 11 advisory(ies): CVE-2026-44294 (protobuf.js: Denial of service from crafted field names in generated code); CVE-2026-44293 (protobuf.js: Code injection through bytes field defaults in generated toObject c); CVE-2026-44289 (protobuf.js: Denial of service through unbounded protobuf recursion) +8 more

Critical
Category
Supply Chain
Confidence
96% confidence
Finding

protobufjs 6.11.4 is a known vulnerable version with multiple advisories including denial of service, recursion-based exhaustion, and possible code-injection issues in generated code paths. Because this package is used transitively by onnx-proto/onnxruntime-web, any workflow that ingests untrusted model or protobuf-derived content could expose the skill to crashes or worse, depending on how code generation features are used.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · TOOLS.md (reported line 36)May include surrounding context.

md
## Why Separate?

Skills are shared. Your setup is yours. Keeping them apart means you can update skills without losing your notes, and share skills without leaking your infrastructure.

---

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · opennews-mcp/README.md (reported line 241)May include surrounding context.

Continue.dev

~/.continue/config.yaml:

yaml
mcpServers:

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · opennews-mcp/docs/README_JA.md (reported line 241)May include surrounding context.

Continue.dev

~/.continue/config.yaml:

yaml
mcpServers:

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · opennews-mcp/docs/README_KO.md (reported line 241)May include surrounding context.

Continue.dev

~/.continue/config.yaml:

yaml
mcpServers:

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · opennews-mcp/docs/README_ZH.md (reported line 241)May include surrounding context.

Continue.dev

~/.continue/config.yaml:

yaml
mcpServers:

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · opentwitter-mcp/README.md (reported line 240)May include surrounding context.

Continue.dev

~/.continue/config.yaml:

yaml
mcpServers:

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · opentwitter-mcp/docs/README_JA.md (reported line 240)May include surrounding context.

Continue.dev

~/.continue/config.yaml:

yaml
mcpServers:

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · opentwitter-mcp/docs/README_KO.md (reported line 240)May include surrounding context.

Continue.dev

~/.continue/config.yaml:

yaml
mcpServers:

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · opentwitter-mcp/docs/README_ZH.md (reported line 240)May include surrounding context.

Continue.dev

~/.continue/config.yaml:

yaml
mcpServers:

Known Vulnerable Dependency: sharp==0.32.6 — 2 advisory(ies): GHSA-f88m-g3jw-g9cj (sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-); GHSA-rgj7-g3m4-5g8c (sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545)

High
Category
Supply Chain
Confidence
91% confidence
Finding

sharp 0.32.6 is flagged for inherited vulnerabilities in native image-processing libraries such as libvips/libheif. If this skill processes attacker-controlled images, those native parsing bugs can lead to denial of service and potentially memory-safety exploitation in the underlying libraries.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The skill instructs users to place PRIVATE_KEY in a .env file in the current working directory. Storing a raw blockchain private key in project-local plaintext materially increases the risk of accidental commit, leakage via tooling, exposure to other local processes, or theft by malicious dependencies reading the working directory.

Content

Scanner excerpt · skills/four-meme-ai/SKILL.md (reported line 171)May include surrounding context.

md
**When not using OpenClaw (standalone)**  
Set **PRIVATE_KEY** and optionally **BSC_RPC_URL** via the process environment so they are available when running `npx fourmeme` or `node bin/fourmeme.cjs`:

- **.env file**: Put a `.env` file in **the directory where you run the `fourmeme` command** (i.e. your project / working directory). Example: if you run `fourmeme quote-buy ...` from `/path/to/my-project`, place `.env` at `/path/to/my-project/.env`. The CLI automatically loads `.env` from that current working directory. Use lines like `PRIVATE_KEY=...` and `BSC_RPC_URL=...`. Do not commit `.env`; add it to `.gitignore`.
- **Shell export**: `export PRIVATE_KEY=your_hex_key` and `export BSC_RPC_URL=https://bsc-dataseed.binance.org` (or another BSC RPC), then run `npx fourmeme <command> ...`.

### Declared and optional environment variables

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · skills/grok-twitter-search/scripts/setup_interactive.py (reported line 202)May include surrounding context.

python
]
    
    if proxy and proxy != "auto":
        env = os.environ.copy()
        env["SOCKS5_PROXY"] = proxy
    else:
        env = os.environ.copy()

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · skills/grok-twitter-search/scripts/setup_interactive.py (reported line 205)May include surrounding context.

python
]
    
    if proxy and proxy != "auto":
        env = os.environ.copy()
        env["SOCKS5_PROXY"] = proxy
    else:
        env = os.environ.copy()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/grok-twitter-search/scripts/setup_interactive.py (reported line 352)May include surrounding context.

python
print("\n💡 WARP 安装指南:")
        print("   Ubuntu/Debian:")
        print("   curl -fsSL https://pkg.cloudflareclient.com/cloudflare-warp.asc | \\")
        print("     sudo gpg --dearmor -o /usr/share/keyrings/cloudflare-warp-archive-keyring.gpg")
        print("   echo 'deb [signed-by=/usr/share/keyrings/cloudflare-warp-archive-keyring.gpg] \\")
        print("     https://pkg.cloudflareclient.com/ $(lsb_release -cs) main' | \\")
        print("     sudo tee /etc/apt/sources.list.d/cloudflare-client.list")

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/grok-twitter-search/scripts/setup_interactive.py (reported line 353)May include surrounding context.

python
print("\n💡 WARP 安装指南:")
        print("   Ubuntu/Debian:")
        print("   curl -fsSL https://pkg.cloudflareclient.com/cloudflare-warp.asc | \\")
        print("     sudo gpg --dearmor -o /usr/share/keyrings/cloudflare-warp-archive-keyring.gpg")
        print("   echo 'deb [signed-by=/usr/share/keyrings/cloudflare-warp-archive-keyring.gpg] \\")
        print("     https://pkg.cloudflareclient.com/ $(lsb_release -cs) main' | \\")
        print("     sudo tee /etc/apt/sources.list.d/cloudflare-client.list")

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · skills/grok-twitter-search/scripts/setup_interactive.py (reported line 356)May include surrounding context.

python
print("   echo 'deb [signed-by=/usr/share/keyrings/cloudflare-warp-archive-keyring.gpg] \\")
        print("     https://pkg.cloudflareclient.com/ $(lsb_release -cs) main' | \\")
        print("     sudo tee /etc/apt/sources.list.d/cloudflare-client.list")
        print("   sudo apt update && sudo apt install cloudflare-warp")
        print("   sudo systemctl start warp-svc")
        print("   warp-cli registration new && warp-cli connect")

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file explicitly says MEMORY.md must only be loaded in main sessions because it may contain personal context, but later heartbeat instructions tell the agent to review and update MEMORY.md without restating or enforcing that boundary. In any shared or loosely scoped heartbeat context, this can cause unauthorized reading, summarization, or propagation of sensitive long-term memory.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · AGENTS.md (reported line 51)May include surrounding context.

md
## Safety

- Don't exfiltrate private data. Ever.
- Don't run destructive commands without asking.
- `trash` > `rm` (recoverable beats gone forever)
- When in doubt, ask.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

These lines switch to Chinese for an operationally important notice, but the file does not offer a language choice or explain a required locale. This can violate language policy expectations by implicitly forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The heartbeat trigger guidance is broad and can activate on a configurable prompt with limited scoping, encouraging the agent to take action whenever a message loosely matches the pattern. That increases the chance of prompt-triggered behavior in unintended contexts, including background checks or outbound notifications not actually authorized by the current user interaction.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
84% confidence
Finding

The file authorizes proactive actions 'without asking,' including reading and organizing memory files, checking projects, and updating documentation. Even if framed as helpful automation, this grants unsupervised access to sensitive local context and can cause unintended data exposure, persistence changes, or repository modifications.

Content

Scanner excerpt · AGENTS.md (reported line 199)May include surrounding context.

md
- Nothing new since last check
- You just checked &lt;30 minutes ago

**Proactive work you can do without asking:**

- Read and organize memory files
- Check on projects (git status, etc.)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file defines a fixed Chinese-language persona ('瓜助理', '技术瓜的 AI 小助理') and communication style without indicating that this should adapt to user preference. This can inappropriately constrain agent behavior, causing unwanted language or persona steering that may reduce usability, mislead users about the assistant's identity, or conflict with deployment requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document includes a destructive find ... -delete command that removes files older than 30 days without any warning, confirmation step, backup guidance, or scope validation. In an agent/skill context, operators may copy-paste or automate this directly, increasing the risk of unintended data loss if the path is wrong, retention assumptions are incorrect, or memory files are still needed.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · QMD-SETUP.md (reported line 143)May include surrounding context.

md
## 📚 文档

- **README**: `/Users/ben/.openclaw/workspace/qmd/README.md`
- **Skill 文档**: `/Users/ben/.openclaw/workspace/skills/qmd-memory/SKILL.md`

---