x-mastery-mentor

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data by scraping tweets from x.com for analysis. Ingestion points: Tweet and profile data from x.com enter the context in SKILL.md (Scene E). Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands in the scraped content. Capability inventory: The skill uses browser automation (computer-use, claude-in-chrome), javascript execution (javascript_tool), and file writing (user-data/) as described in SKILL.md. Sanitization: No sanitization or filtering of tweet content is specified before processing.
  • [COMMAND_EXECUTION]: The skill employs platform-provided browser automation and Javascript tools to interact with the DOM of x.com pages to extract tweet data for diagnostics.
  • [DATA_EXFILTRATION]: The skill stores analyzed user data and diagnostic reports in a local directory (user-data/). This data collection is transparently linked to the primary mentoring and diagnostic function.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 08:13 AM