twitter-agent
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from Twitter mentions, which creates a surface for potential indirect prompt injection attacks.
- Ingestion points: The agent fetches external content from the Twitter API using the
userMentionTimelineexpansion, as described in the Reply Workflow section ofSKILL.md. - Boundary markers: While explicit prompt delimiters are not defined in the skill instructions, the agent is directed to prioritize content and rank mentions, providing a layer of processing between ingestion and drafting.
- Capability inventory: The skill utilizes
execute_clito perform network operations (Twitter API) andedit_fileto maintain persistent lore and storyline state, creating a capability chain that processes external data and saves narrative updates. - Sanitization: The skill includes robust mitigations, such as the "Never Reply Unprompted" filter, a comprehensive "Skip List" for trolls and spam, and mandatory manual approval via Telegram for any drafts matching specific guardrail patterns like cryptocurrency addresses or mentions of
@bankrbot.
Audit Metadata