x-hashtag-research
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it collects and processes untrusted public data from X (Twitter).
- Ingestion points: The workflow in
SKILL.mddescribes extracting data from X live search, including post text, display text, and card titles (Steps 2 and 4). - Boundary markers: There are no explicit instructions to use delimiters or ignore instructions embedded within the processed posts.
- Capability inventory: The skill has file-write capabilities (saving to
tmp/andresearch/) and network access via browser tools to resolve links and download images (Steps 3, 5, and 7). - Sanitization: The instructions do not specify any sanitization or validation of the content gathered from the external platform before it is used for local classification or deep-linking.
Audit Metadata