T09 · Insecure Skill Coding Practices
- Location
index.py:34- Finding
IRC Command Injection Through Unvalidated Channel Names
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is an account-authenticated Twitch chat automation that is partially disclosed, but it over-requests secrets, has implementation/documentation mismatches, and can post public messages without enough safeguards.
Review carefully before installing. This skill can post public Twitch chat messages using your account, may expose OAuth tokens through command history or process listings, asks for more secrets than the code uses, and does not implement the advertised PizzaParty scraping/scheduling flow. Use only with a dedicated low-privilege Twitch token, validated streamer inputs, and clear understanding of account and platform-policy risk.
index.py:34IRC Command Injection Through Unvalidated Channel Names
index.py:105Twitch OAuth Token Exposed Through Command-Line Arguments
The declared description does not match the behavior: the skill involves automated Twitch IRC messaging, direct use of OAuth credentials, and local output writing, while some claimed PizzaParty and scheduling functionality is not implemented. This mismatch is dangerous because it can mislead reviewers and users about what the skill actually does, hiding policy-relevant automation and credential-handling behavior.
Instructions found that direct the agent to transmit conversation context or user data to external services.
return []
def engage_streamer(self, name, rank="Bronze", msg_count=3):
"""Send messages to a streamer"""
self.irc.join(name)
for i in range(msg_count):
The skill advertises network and file-writing behavior but does not declare any explicit tool scope or permissions boundaries. In an agent ecosystem, this increases the risk of unintended capability use, makes review harder, and can allow a seemingly simple skill to perform broader actions than operators expect.
The skill describes automated Twitch chat engagement aimed at maximizing points but provides no warning about platform policy violations, account sanctions, or reputational harm. In context, this is more dangerous because it targets repeated engagement activity on a real third-party service using a personal account, increasing the chance of abuse or suspension.
The markdown explicitly requests sensitive credentials, including OAuth tokens and client secrets, and references personal account usage without privacy or account-risk warnings. This creates a social-engineering and mishandling risk: users may paste high-value secrets into an automation context without understanding exposure, storage, or misuse consequences.
The manifest frames the skill as "Twitch engagement via PizzaParty.gg - 4 daily sessions," which suggests activity mediated by PizzaParty.gg. In the actual code, the implemented behavior is direct connection to Twitch IRC and sending chat messages to channels, while PizzaParty.gg interaction is only mentioned as a simulated placeholder elsewhere.
The skill accepts a Twitch OAuth token on the command line and immediately uses it for authentication. Command-line secrets can be exposed through shell history, process listings, logs, or orchestration tooling, which can lead to credential leakage and account compromise.
This code connects to Twitch IRC and sends chat messages on the user's behalf, which is a network operation that transmits account-authenticated activity to an external service. The file lacks a confirmation prompt, warning print/log, or explanatory comment/docstring disclosing that real outbound chat messages will be posted.
The function documentation says it would use Playwright to scrape PizzaParty and implies it returns streamer data, but the implementation simply returns an empty list and performs no scraping. This is an active mismatch between documented intent and actual behavior, not just missing detail.
The script writes engagement results to a JSON file on disk, which is a file-write operation affecting local user data. Although the output path is configurable, the code does not provide any explicit warning, confirmation, or user-facing notice that a file will be created or overwritten.
No suspicious patterns detected.