skills/cursor/plugins/X Money guide/Gen Agent Trust Hub

X Money guide

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions to prioritize user-friendly language over technical implementation details (e.g., "instead of describing internals"). While heuristic detectors may flag this as concealment, in context, this is benign UX guidance intended to prevent confusing the user with backend technicalities and does not bypass safety guardrails.
  • [CREDENTIALS_UNSAFE]: The skill demonstrates positive security practices by explicitly forbidding the agent from asking for passwords, passkeys, or card details, and directing the agent never to output sensitive information like CVC or card numbers in the chat.
  • [EXTERNAL_DOWNLOADS]: The skill references an official MCP server and settings pages on the x.com domain. These are well-known service endpoints associated with the skill's primary purpose and do not represent a security risk.
  • [DATA_EXFILTRATION]: There are no patterns suggesting data exfiltration. The instructions are designed to manage transaction outcomes and errors through official channels.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 09:41 PM
Security Audit — agent-trust-hub — X Money guide