Back to skill

Security audit

Xquik X API

Security checks across malware telemetry and agentic risk

Overview

The skill is a broad Xquik/X integration guide with sensitive capabilities, but its main instructions disclose them and require user approval before private reads, writes, persistent resources, webhooks, and metered jobs.

Install only if you trust Xquik with your Xquik API key and any account-scoped X data you request. Keep public reads bounded, require explicit confirmation before writes, DMs, exports, media galleries, monitors, webhooks, cached styles, or deletes, and avoid sending secrets or unnecessary personal data in support tickets or prompts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The file documents `POST /drafts` and a draft deletion operation even though the skill metadata emphasizes 'read-only by default' and says writes require explicit approval. This mismatch can cause an agent or operator to assume the skill is non-destructive when it actually exposes write capabilities, increasing the risk of unintended state changes or unsafe autonomous use.

Description-Behavior Mismatch

Low
Confidence
82% confidence
Finding
Draft-management functionality is present in the endpoint documentation but not reflected in the stated triggers and scope of the skill. Incomplete capability disclosure weakens user and agent understanding of what the skill can do, which can lead to misuse, overbroad trust, or approval workflows that fail to account for hidden write features.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The documentation exposes a state-changing endpoint (`POST /draws`) in a skill described as read-only by default with explicit approval required for writes. In an agent setting, this mismatch can cause unintended giveaway execution if the write capability is surfaced or invoked without a clear approval gate.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
This documentation exposes state-changing monitor operations even though the skill metadata says the capability is read-only by default and requires explicit approval for writes, monitors, webhooks, and metered bulk jobs. In an agent setting, mismatch between safety posture and endpoint docs can cause the model or operator to invoke monitor creation, modification, or deletion without the intended approval gate, enabling persistent surveillance or destructive changes.

Intent-Code Divergence

Low
Confidence
87% confidence
Finding
The keyword monitor section advises users to confirm query, delivery plan, and usage, but the documented API shape still presents immediate create/update/delete operations with no stated enforcement. In an autonomous or semi-autonomous agent workflow, soft guidance is often insufficient, so persistent monitoring could be enabled without a meaningful consent checkpoint.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
This file documents numerous write-capable and destructive actions such as tweeting, deleting tweets, sending DMs, following users, and profile updates, but it does not preserve the skill-level safety constraint that the integration is read-only by default and requires explicit approval for writes. In an agent setting, missing local guardrails in the write reference increases the chance that downstream tooling or prompts invoke impactful actions without clear consent boundaries, causing unauthorized account actions or reputation damage.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
Exporting winners or full entries can expose participant data at scale, especially when `entries` exports may include large volumes of usernames, engagement records, or other identifying metadata. The absence of warnings, minimization guidance, or access restrictions increases the risk of privacy leakage and misuse in downstream storage or sharing.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The delete monitor endpoint states that it stops tracking and deletes all associated data, but it does not document any warning, confirmation, or safeguard. In an agent-integrated skill, undocumented destructive behavior increases the risk of accidental or unauthorized deletion of monitoring configuration and collected data.

Missing User Warnings

Low
Confidence
90% confidence
Finding
The documentation describes submitting free-form ticket subjects and bodies without warning that users may include credentials, personal data, or proprietary content that will be transmitted to the service. In a skill advertised as read-only by default, undocumented transmission of sensitive text to support systems increases the risk of accidental data disclosure and inappropriate sharing of conversation context or scraped content.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The `/styles` endpoint explicitly fetches and caches recent tweets from another X account, but the documentation provides no privacy, consent, retention, or acceptable-use warning. In a scraping/export skill, that omission can normalize collection and storage of third-party content without informing users about legal, privacy, and platform-policy risks, especially since the endpoint persists tweet data for later retrieval and comparison.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The delete endpoint removes cached styles by label or username and returns `204 No Content`, but the documentation lacks any warning that this is destructive and potentially irreversible. In a skill that caches metered results and may store custom styles, users could accidentally delete data they paid to generate or intended to preserve, increasing the risk of unintended data loss.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The documentation states that downloads are saved to shareable gallery pages, but it does not clearly warn users up front that submitted tweet media will be persisted and exposed via a public/shareable URL. In a read-oriented scraping skill, this creates a real privacy and data-handling risk because users may assume the action is a transient fetch rather than publication to a gallery accessible by anyone with the link.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
High-impact operations including delete tweet, send DM, follow/unfollow, remove follower, profile edits, community deletion, and media/profile changes are documented with little or no explicit user-warning language. In agent-controlled workflows, this omission can normalize risky actions and lead to accidental destructive behavior, privacy violations, or impersonation-like account modifications without sufficient confirmation.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The documentation explicitly enables bulk extraction, retrieval, and export of user and tweet data at scale, but does not include meaningful privacy, acceptable-use, retention, or consent guidance. In a scraping/extraction skill, this omission increases the risk that operators will collect, export, and redistribute personal or behavioral data without appropriate safeguards, making misuse easier even if the underlying capability is intentional.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The examples authenticate to an external third-party API using an environment-stored API key but do not clearly warn that running them will transmit authenticated requests, queries, and potentially sensitive account-scoped data off-platform. In this skill’s context, the service can access private or sensitive X data such as bookmarks, notifications, timelines, and DM history, so omission of an explicit warning and consent boundary increases the risk of unintended data disclosure or misuse.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The endpoint guide enumerates numerous write and account-affecting operations such as posting tweets, likes, follows, DMs, profile updates, and media uploads without a strong, centralized warning that these actions mutate the user’s account and may incur charges or persistent effects. Although some earlier text mentions explicit approval for certain operations, the guide itself presents dangerous endpoints in a reference format that could normalize their use without sufficient friction or confirmation.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.