twitter-thread-creation

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation references external installation instructions for the belt CLI hosted on a public GitHub repository (inference-sh/skills). This is provided to the user as a prerequisite for using the skill's functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that ingests data from external research tools and uses it to perform automated actions, creating a potential surface for indirect prompt injection.
  • Ingestion points: Untrusted data enters the agent's context through the tavily/search-assistant tool, which is used to research statistics and source material.
  • Capability inventory: The skill utilizes the x/post-create tool to publish content to social media and infsh/html-to-image for visual content generation.
  • Boundary markers: The provided command templates do not include specific delimiters or "ignore" instructions to separate the ingested research data from the agent's primary task instructions.
  • Sanitization: There is no evidence of content validation or sanitization of the research output before it is interpolated into the social media post templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:54 PM
Security Audit — agent-trust-hub — twitter-thread-creation