skills/defuj/opencode-agent-kit/x-api/Gen Agent Trust Hub

x-api

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and code examples for interacting with the X (Twitter) API.
  • [CREDENTIALS_UNSAFE]: The skill demonstrates best practices for credential management by explicitly instructing users to use environment variables (e.g., X_BEARER_TOKEN, X_CONSUMER_KEY) rather than hardcoding secrets. It also includes specific warnings against committing .env files to version control.
  • [EXTERNAL_DOWNLOADS]: The skill uses well-known and trusted Python libraries (requests, requests_oauthlib) for network communication with official API endpoints (api.x.com, upload.twitter.com).
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from the X API (tweets, timelines). While this introduces a surface for indirect prompt injection, the skill acts as a bridge for programmatic interaction and follows standard data handling patterns. The associated risk is low as it does not automatically execute instructions found in the ingested data.
  • [COMMAND_EXECUTION]: The provided code snippets involve standard HTTP requests and file reading for media uploads, with no dangerous subprocess execution or shell injection patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — x-api