xquik-x-research
Fail
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: CRITICAL
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill identifies that data retrieved from X (Twitter) is untrusted. It mitigates injection risks by requiring the agent to wrap all such content in
<XQUIK_UNTRUSTED_X_CONTENT>tags and providing explicit instructions to ignore any commands or instructions found within the processed text. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill follows least-privilege principles for credentials. It only uses the
XQUIK_API_KEYvia environment variables and contains strong prohibitions against requesting sensitive user data such as passwords, 2FA codes, session cookies, or browser profiles. API requests are directed to the vendor's primary domain atxquik.com. - [EXTERNAL_DOWNLOADS]: Instructions are included to install the full version of the tool via
npx skills@1.5.3 add Xquik-dev/x-twitter-scraper. This is a standard package installation referencing the vendor's official repository for extended functionality.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata