x-bookmark-quote-posts

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the processing of external social media content. Ingestion points: As defined in SKILL.md, the agent fetches untrusted data from X (Twitter) bookmarks and user timelines. Boundary markers: The instructions lack specific delimiters or protective prompts to prevent the agent from interpreting instructions contained within the scraped tweets. Capability inventory: The skill utilizes Bash, Write, and Edit tools, allowing for file modifications and command execution. Sanitization: No mechanism is described for sanitizing or filtering the fetched content before it is used for calibration and drafting.
  • [DATA_EXFILTRATION]: The skill handles sensitive user information by design. Evidence: The core function involves accessing a user's private bookmarks and full post history on X (Twitter). Note: While the intended use is local draft generation, the access to authenticated personal data represents a potential privacy risk if the agent's execution flow is subverted.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 03:01 AM
Security Audit — agent-trust-hub — x-bookmark-quote-posts