X MCP guide
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill integrated tools to read external content from X, such as posts, news, and user profiles (e.g.,
search_posts_all,get_news,get_users_posts). This data originates from untrusted external users and could contain malicious instructions intended to influence the agent's behavior. - Ingestion points: Data enters the agent's context through tools that fetch posts, user profiles, and news stories from the X platform.
- Boundary markers: The instructions do not explicitly mandate the use of delimiters or specific warnings to ignore instructions embedded in external content.
- Capability inventory: The agent has write capabilities, such as creating bookmarks and sending chat messages or replies.
- Sanitization: No specific sanitization or filtering of external content is mentioned before it is processed by the agent.
- [EXTERNAL_DOWNLOADS]: The instructions guide the agent or user to clone a helper repository (
https://github.com/xdevplatform/xchat-grokbot-helper) to support encrypted X Chat features. This involves referencing external code from a GitHub repository outside of the primary vendor's infrastructure.
Audit Metadata