Chirp

PassAudited by ClawScan on May 10, 2026.

Overview

Chirp is a transparent browser-based X/Twitter helper, but it uses your logged-in X session and can perform public account actions when directed.

Only install or invoke this skill if you want OpenClaw to use a logged-in X/Twitter browser session. Before any post, reply, repost, like, or follow, confirm the exact action and account, and consider using a separate browser profile to limit account exposure.

Findings (2)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

If used, the agent can act as the logged-in X/Twitter account within the browser session.

Why it was flagged

The skill relies on a logged-in browser profile, which means actions are performed with the user's X/Twitter account privileges.

Skill content
- `openclaw` browser profile
- X/Twitter 계정 로그인 완료
Recommendation

Use a dedicated browser profile or test account if possible, and log out or remove the profile when you no longer want the agent to have access.

What this means

Mistaken or over-broad use could post, reply, like, repost, or follow from the user's account.

Why it was flagged

The browser tool is used for account-changing social actions. This is disclosed and aligned with the skill purpose, but the actions can affect public content and account state.

Skill content
Use when the user wants to interact with X/Twitter: reading timeline, posting tweets, liking, retweeting, replying, or searching.
Recommendation

Require explicit user confirmation for every account-changing action, not only tweets, and review browser snapshots before clicking publish/repost/follow/like controls.