Back to skill

Security audit

hume-x

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed X/Twitter CLI, but it asks users to install an unaudited global package that can use browser session cookies and perform live account actions.

Review this carefully before installing. Use a dedicated or low-risk X account if possible, avoid passing tokens on the command line, do not allow browser-cookie access unless you understand it, and prefer a pinned or otherwise verified package version before granting it account credentials.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:4
Finding

Unpinned Third-Party Package Installed Globally

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:13
Finding

Automatic Discovery of Sensitive X Session Credentials from Browser Profiles and Local Stores

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
94% confidence
Finding

Automatic use of browser cookies from Firefox or Chrome matches credential-stealing patterns because it relies on accessing local browser session data to authenticate. Even if intended for convenience rather than theft, this is high-risk in a skill because browser cookies are powerful bearer credentials and their silent reuse can expose the user's account if mishandled, logged, or transmitted unexpectedly.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

h. Full API coverage for tweets, timelines, search, engagement, social, lists, trending, notifications, bookmarks, likes, and scheduled tweets.

Authentication

Uses cookie-based auth. Credentials are resolved in order:

  1. CLI flags: --auth-token and --ct0
  2. Environment variables: X_AUTH_TOKEN + X_CT0 (or AUTH_TOKEN + CT0)
  3. Config file: ~/.config/hume-x/config.json
  4. Browser cookies: Firefox (preferred) or Chrome

Run hume-x check to verify credentials. Use hume-x whoami to see the logged-in user.

Posting

bash
hume-x tweet "hello world"
hume-x tweet "check this out" --media image.png --alt "description"
hume-x reply <id-or-url> "nice thread!"
hume-x quote <id-or-url> "interesting take"
hume-x delete <tweet-id>

Supports media upload: images (jpg/png/webp), GIFs, videos with chunked upload.

Reading

bash
hume-x read <id-or-url>
hume-x thread <id-or-url>
hume-x replies <id-or-url> -n 50

Accepts tweet ID or full URL (e.g. `https://x.com/us

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly documents multiple ways to supply or discover live X authentication material, including automatic extraction from local browser cookies. That creates a real security risk because users may expose highly sensitive session tokens to a third-party CLI without an explicit warning about token handling, local cookie access, or the consequences of session compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill advertises account-affecting actions such as tweet, reply, quote, and delete without any caution about irreversible or public consequences. In an agent/automation context, this increases the chance of unintended posting or destructive actions on a user's social account, especially if combined with stored credentials.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.