AI agent for X/Twitter with full read + write capabilities. Free reads via twitter-cli, writes via official X API MCP server.
Drift inferred · capture-to-capture
No drift recorded — single capability capture; advisories appear once its surface changes.
transport stdio · streamable-http · http counts 0 tools · 0 res
· 0 prompts
permission surface via code analysis
No tools enumerated yet for this server.
prompt-surface
shipped agent-instruction files + hidden-content / dangerous-code findings —
quoted from the analyzed source
analyzed commit e312b0c · analyzer v33 · 1w ago
skills & prompt files 1
danger signals1
- credential in logs credential in log Kevin-Liu-01-X-Agent-e312b0c/xmcp/server.py :378
print("OAuth1 access token:", access_token)
evidence-backed
findings quoted directly from the published source artifact — not inferred
code files: 4
filesystem 3
- fs Kevin-Liu-01-X-Agent-e312b0c/xmcp/auth.py :4
from pathlib import Path - fs Kevin-Liu-01-X-Agent-e312b0c/xmcp/server.py :11
from pathlib import Path - fs Kevin-Liu-01-X-Agent-e312b0c/xmcp/test_grok_mcp.py :2
from pathlib import Path
network 1
- net Kevin-Liu-01-X-Agent-e312b0c/xmcp/server.py :9
import urllib.parse
secrets 2
- secrets Kevin-Liu-01-X-Agent-e312b0c/xmcp/server.py :156
consumer_key = os.getenv("X_OAUTH_CONSUMER_KEY") - secrets Kevin-Liu-01-X-Agent-e312b0c/xmcp/test_grok_mcp.py :21
api_key = os.getenv("XAI_API_KEY", "").strip()
declared dependencies 6
- fastmcp@*
- httpx@*
- python-dotenv@*
- requests-oauthlib@*
- xai-sdk@*
- xdk@*
cursor-plugin 2
- opaque (low) Kevin-Liu-01-X-Agent-e312b0c/.cursor/mcp.json
bundled .cursor/ plugin descriptor (Kevin-Liu-01-X-Agent-e312b0c/.cursor/mcp.json) — presence-detected; review the descriptor - opaque (low) Kevin-Liu-01-X-Agent-e312b0c/.cursor/rules/x-agent.mdc
bundled .cursor/ plugin descriptor (Kevin-Liu-01-X-Agent-e312b0c/.cursor/rules/x-agent.mdc) — presence-detected; review the descriptor