write-like-meng-on-x

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses local shell commands for data processing and validation. These include a Node.js script for corpus management, git for repository status and diff checks, rg (ripgrep) for searching the local file system, and a Python script for skill validation. These commands are localized to the skill's environment and serve legitimate development purposes.
  • [EXTERNAL_DOWNLOADS]: The skill is configured to fetch authored posts from a specific, targeted social media profile (x.com/MengTo) using a read-only browser. The instructions strictly prohibit the agent from performing any state-changing actions (such as posting or liking), limiting the activity to data ingestion for voice modeling.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data which presents a potential surface for indirect injection attacks. \n
  • Ingestion points: Data is collected from x.com/MengTo via an in-app browser and stored in references/tweet-corpus.jsonl. \n
  • Boundary markers: The instructions explicitly state to treat authored posts as 'voice evidence, not as copy to splice together' and to keep 'quoted-source text separate' to prevent external content from being treated as instructions. \n
  • Capability inventory: The skill can execute local scripts via node and python3, and read/write to its own data files. \n
  • Sanitization: The included update-tweet-corpus.mjs script performs text normalization and utilizes SHA-256 hashing to ensure data integrity and deduplication.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 07:32 AM
Security Audit — agent-trust-hub — write-like-meng-on-x