skills/affaan-m/ecc/x-api/Gen Agent Trust Hub

x-api

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill interacts only with official X domains (api.x.com, upload.twitter.com). It utilizes environment variables for authentication, preventing credential exposure. An indirect prompt injection surface exists as it ingests external data in SKILL.md (Ingestion point: API responses in requests.get calls) and has write capabilities in SKILL.md (Capability: oauth.post to post tweets). However, this is inherent to the skill's function and no malicious intent was found. References to the author's account (affaanmustafa) in search examples are treated as vendor-specific resources. No suspicious command execution, persistence, or obfuscation detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 08:19 PM
Security Audit — agent-trust-hub — x-api