skills/cursor/plugins/X Chat/Gen Agent Trust Hub

X Chat

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires downloading a helper repository from the X development platform's GitHub organization and installing the chatxdk package from PyPI.
  • [COMMAND_EXECUTION]: Local shell commands are used to manage encryption and decryption through a helper script, utilizing variable interpolation for user IDs and file paths.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted text from X DMs which could contain malicious instructions. While the instructions include a safety section to mitigate this, the attack surface remains.
  • Ingestion points: Message content is retrieved via the get_chat_conversation_events tool.
  • Boundary markers: The skill contains explicit instructions to treat inbound text as untrusted data rather than instructions.
  • Capability inventory: The skill can execute shell commands, perform network operations via the X MCP, and manage local files.
  • Sanitization: The skill relies on model-level instructions to ignore embedded commands in decrypted text.
  • [DYNAMIC_EXECUTION]: The skill executes a downloaded Python script (xchat_lite.py) to perform cryptographic operations on-the-fly.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:11 PM
Security Audit — agent-trust-hub — X Chat