twitter-agent

Pass

Audited by Gen Agent Trust Hub on Apr 25, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted text from external Twitter mentions, creating a potential surface for indirect prompt injection.\n- Ingestion points: Fetches mention data via the X API userMentionTimeline expansion as described in SKILL.md.\n- Boundary markers: The skill does not explicitly define delimiters for external content in the draft prompt construction.\n- Capability inventory: The agent can post tweets, reply to users, and update persistent storyline and personality files.\n- Sanitization: Implements comprehensive filtering and mandatory manual approval for drafts involving EVM/Solana addresses, transaction-like language, or mentions of the platform's treasury bot.\n- [COMMAND_EXECUTION]: Utilizes the execute_cli tool to run JavaScript/TypeScript scripts through the bun runtime for all Twitter API communications.\n- [EXTERNAL_DOWNLOADS]: Fetches the standard twitter-api-v2 package from the official NPM registry for social media automation tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 25, 2026, 07:08 PM