T08 · Insecure Dependencies
- Location
SKILL.md:4- Finding
Unpinned Third-Party Package Installed Globally
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed X/Twitter CLI, but it asks users to install an unaudited global package that can use browser session cookies and perform live account actions.
Review this carefully before installing. Use a dedicated or low-risk X account if possible, avoid passing tokens on the command line, do not allow browser-cookie access unless you understand it, and prefer a pinned or otherwise verified package version before granting it account credentials.
SKILL.md:4Unpinned Third-Party Package Installed Globally
SKILL.md:13Automatic Discovery of Sensitive X Session Credentials from Browser Profiles and Local Stores
Automatic use of browser cookies from Firefox or Chrome matches credential-stealing patterns because it relies on accessing local browser session data to authenticate. Even if intended for convenience rather than theft, this is high-risk in a skill because browser cookies are powerful bearer credentials and their silent reuse can expose the user's account if mishandled, logged, or transmitted unexpectedly.
h. Full API coverage for tweets, timelines, search, engagement, social, lists, trending, notifications, bookmarks, likes, and scheduled tweets.
Uses cookie-based auth. Credentials are resolved in order:
--auth-token and --ct0X_AUTH_TOKEN + X_CT0 (or AUTH_TOKEN + CT0)~/.config/hume-x/config.jsonRun hume-x check to verify credentials. Use hume-x whoami to see the logged-in user.
hume-x tweet "hello world"
hume-x tweet "check this out" --media image.png --alt "description"
hume-x reply <id-or-url> "nice thread!"
hume-x quote <id-or-url> "interesting take"
hume-x delete <tweet-id>
Supports media upload: images (jpg/png/webp), GIFs, videos with chunked upload.
hume-x read <id-or-url>
hume-x thread <id-or-url>
hume-x replies <id-or-url> -n 50
Accepts tweet ID or full URL (e.g. `https://x.com/us
The skill explicitly documents multiple ways to supply or discover live X authentication material, including automatic extraction from local browser cookies. That creates a real security risk because users may expose highly sensitive session tokens to a third-party CLI without an explicit warning about token handling, local cookie access, or the consequences of session compromise.
The skill advertises account-affecting actions such as tweet, reply, quote, and delete without any caution about irreversible or public consequences. In an agent/automation context, this increases the chance of unintended posting or destructive actions on a user's social account, especially if combined with stored credentials.
No suspicious patterns detected.