twitter-cli
What this skill does
Twitter/X CLI tool for reading and writing tweets, user interactions, and other social media operations
github/public-clis - Privilege Escalation - 2.8k stars
Threat analysis
Skill info
pkg:github/public-clis/twitter-cli@7c634e0?skill=twitter-cliAssessments (3)
Privilege Escalation
Privilege Escalation via local-llm-review
twitter_cli/auth.py
The code attempts to extract browser cookies for authentication, which may involve accessing sensitive user data stored in the browser's keychain or cookie storage. This could be a privacy concern if Obfuscation
Obfuscation via local-llm-review
twitter_cli/constants.py
The string 'AAAAAAAAAAAAAAAAAAAAANRILgAAAAAAnNwIzUejRCOuH5E6I8xnZz4puTs' appears to be obfuscated or placeholder data, which may be used for testing or as a placeholder for real tokens or keys.Obfuscation via local-llm-review
twitter_cli/graphql.py
The string 'twitter-openapi/refs/heads/main/src/config/placeholder.json' appears to be a placeholder or obfuscated reference to a configuration file, which may be used for testing or as a placeholder Badge
Add the Anomity scan badge for twitter-cli to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of twitter-cli? Report an issue or request a rescan.




