skills/bankrbot/skills/twitter-agent/Gen Agent Trust Hub

twitter-agent

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from Twitter mentions, which creates a surface for potential indirect prompt injection attacks.
  • Ingestion points: The agent fetches external content from the Twitter API using the userMentionTimeline expansion, as described in the Reply Workflow section of SKILL.md.
  • Boundary markers: While explicit prompt delimiters are not defined in the skill instructions, the agent is directed to prioritize content and rank mentions, providing a layer of processing between ingestion and drafting.
  • Capability inventory: The skill utilizes execute_cli to perform network operations (Twitter API) and edit_file to maintain persistent lore and storyline state, creating a capability chain that processes external data and saves narrative updates.
  • Sanitization: The skill includes robust mitigations, such as the "Never Reply Unprompted" filter, a comprehensive "Skip List" for trolls and spam, and mandatory manual approval via Telegram for any drafts matching specific guardrail patterns like cryptocurrency addresses or mentions of @bankrbot.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:45 AM
Security Audit — agent-trust-hub — twitter-agent