bird-cli
Fail
Audited by Snyk on Feb 14, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.90). The prompt explicitly includes CLI flags and examples that pass authentication cookies/tokens (e.g., --auth-token, --ct0 and export AUTH_TOKEN="your-token") which enables and may lead an agent to request and echo secret values verbatim, so it presents a high exfiltration risk.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill fetches and reads user-generated content directly from X/Twitter (tweets, threads, search results, mentions, bookmarks, lists, and news/trending) via X's GraphQL API/browser cookie authentication, so it ingests untrusted third‑party content.
Audit Metadata