baoyu-danger-x-to-markdown

Fail

Audited by Snyk on Aug 21, 2026

Risk Level: HIGH
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The skill reads outsider-authored free text/content at runtime by fetching a user-supplied X URL (tweet/article) and then ingesting/parsing the returned tweet/article text and media URLs into markdown via scripts/main.ts → tweet-to-markdown/thread/graphql + scripts/markdown.ts → formatArticleMarkdown.

HIGH W008: Secret detected in skill content (API keys, tokens, passwords).

  • Secret detected (high risk: 1.00). I flagged a hardcoded, high-entropy bearer token. In scripts/constants.ts there is a literal DEFAULT_BEARER_TOKEN value ("Bearer AAAAA...") — this is not a placeholder like "YOUR_API_KEY" and appears to be a usable bearer token (high-entropy string). Other strings in the repo (user-agent, cookie names, query IDs, env var names) are documentation/config values or low-entropy and were ignored.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W008
HIGH

Secret detected in skill content (API keys, tokens, passwords).

Audit Metadata
Risk Level
HIGH
Analyzed
Aug 21, 2026, 02:09 AM
Issues
2