extension-posting-to-x
Fail
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the x-client library from the mops.one package registry, which is the standard repository for Motoko language dependencies.
- [COMMAND_EXECUTION]: Instructs the user to execute the command mops add x-client@0.2.3 to install the required package.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of untrusted content that is subsequently transmitted to an external service. Evidence chain: (1) Ingestion points: Untrusted text is accepted via the body parameter in the tweet function within src/backend/mixins/x-posting.mo. (2) Boundary markers: No delimiters or specific instructions are provided to the agent to treat the body content as plain text or to ignore embedded instructions. (3) Capability inventory: The skill utilizes the TweetsApi.createPosts capability in src/backend/lib/x.mo to perform network write operations. (4) Sanitization: The provided logic does not include sanitization or validation steps to scrub the input text before it is sent to the X API.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata