x-api
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill interacts only with official X domains (api.x.com, upload.twitter.com). It utilizes environment variables for authentication, preventing credential exposure. An indirect prompt injection surface exists as it ingests external data in
SKILL.md(Ingestion point: API responses inrequests.getcalls) and has write capabilities inSKILL.md(Capability:oauth.postto post tweets). However, this is inherent to the skill's function and no malicious intent was found. References to the author's account (affaanmustafa) in search examples are treated as vendor-specific resources. No suspicious command execution, persistence, or obfuscation detected.
Audit Metadata