x-mastery-mentor
Fail
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: Automated security scanners identified a malicious file within the skill's research directory.
- Evidence: The file
references/research/05-ai-tech-niche.mdwas flagged asFileRepMalware [Misc]. While the file appears to be a markdown document, the direct detection by reputation scanners indicates a severe security risk within the package. - Evidence: Installation via
npx skills add alchaincyf/x-mentor-skillexecutes remote code from the npm registry. While common for skill deployment, this combines with the existing malware flag to elevate risk. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill automates the extraction and local storage of user-specific data from the web.
- Evidence: Scenario E (Account Diagnosis) instructs the agent to scrape up to 100 tweets from a specific X.com profile and save the results, including interaction counts and timestamps, into the
user-data/{username}/directory. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data from X.com as its primary input for analysis, creating a high-risk surface.
- Ingestion points: The skill uses
computer-useor browser tools to navigate to public X profiles and capture tweet content (SKILL.md, Scenario E). - Boundary markers: Absent; there are no instructions for the agent to use delimiters or ignore instructions that may be embedded within the scraped tweet text.
- Capability inventory: The agent has filesystem write access to the
user-data/directory and full browser navigation capabilities to interact with X.com. - Sanitization: Absent; there is no evidence of filtering, escaping, or validation of the ingested tweet data before it is processed by the model to generate reports.
- [COMMAND_EXECUTION]: Extensive use of automated browser control and computer interaction tools.
- Evidence: The skill explicitly directs the agent to use
computer-useto navigate tox.com, take screenshots, and scroll through pages to accumulate data. This level of autonomy in a browser environment can be redirected to perform unintended actions if the agent encounters malicious content.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
Audit Metadata