Get a demo — 30 minutes →
Skill scan report

twitter-cli

View on GitHub
45 Medium This skill contains obfuscated or hidden content. Automated analysis flagged 1 additional risk pattern.

What this skill does

Twitter/X CLI tool for reading and writing tweets, user interactions, and other social media operations

github/public-clis - Privilege Escalation - 2.8k stars

ThreatsPrivilege Escalation Obfuscation

Threat analysis

Privilege Escalation1 finding
Obfuscation2 findings

Skill info

Namepublic-clis/twitter-cli
Registrygithub
Version7c634e0
PURLpkg:github/public-clis/twitter-cli@7c634e0?skill=twitter-cli
Stars2.8k

Assessments (3)

Privilege Escalation1 finding HIGH
HIGH

Privilege Escalation via local-llm-review

twitter_cli/auth.py

The code attempts to extract browser cookies for authentication, which may involve accessing sensitive user data stored in the browser's keychain or cookie storage. This could be a privacy concern if 
Obfuscation2 findings MEDIUM
MEDIUM

Obfuscation via local-llm-review

twitter_cli/constants.py

The string 'AAAAAAAAAAAAAAAAAAAAANRILgAAAAAAnNwIzUejRCOuH5E6I8xnZz4puTs' appears to be obfuscated or placeholder data, which may be used for testing or as a placeholder for real tokens or keys.
MEDIUM

Obfuscation via local-llm-review

twitter_cli/graphql.py

The string 'twitter-openapi/refs/heads/main/src/config/placeholder.json' appears to be a placeholder or obfuscated reference to a configuration file, which may be used for testing or as a placeholder 

Badge

Add the Anomity scan badge for twitter-cli to your README.

Anomity Skill Check badge

Markdown
[![Anomity Skill Check](https://anomity.ai/skills/badge.svg)](https://anomity.ai/skills/github/public-clis/twitter-cli/)
HTML
<a href="https://anomity.ai/skills/github/public-clis/twitter-cli/"><img src="https://anomity.ai/skills/badge.svg" alt="Anomity Skill Check"></a>
Image URL
https://anomity.ai/skills/badge.svg

How Anomity governs this at runtime

Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.

Book a 30-minute demo to see your own skill inventory.

Methodology and disputes

Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of twitter-cli? Report an issue or request a rescan.

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok