x-mastery-mentor

Fail

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: CRITICALDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill uses a javascript_tool to dynamically parse DOM elements on external websites (X.com), posing a runtime execution risk. It also generates diagnostic reports in HTML format that include external JavaScript libraries (ECharts.js) via CDN, which could execute arbitrary code when the reports are viewed in a browser environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection. Ingestion points: Scene E in SKILL.md scrapes user profiles and tweet history from X.com. Boundary markers: The skill lacks delimiters or warnings to ignore instructions within the scraped text. Capability inventory: The skill uses browser automation (computer-use), JavaScript execution (javascript_tool), and file writing to the user-data/ directory. Sanitization: There is no evidence of sanitization or escaping of the scraped content before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill utilizes platform browser automation tools (computer-use and claude-in-chrome) to interact with social media pages, allowing for automated data collection that could inadvertently capture authenticated session data.
  • [DYNAMIC_EXECUTION]: Automated security scans identified references/research/05-ai-tech-niche.md as a malicious file (FileRepMalware), which is a critical finding for this skill repository.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 21, 2026, 10:11 AM
Security Audit — agent-trust-hub — x-mastery-mentor