x-bookmark-quote-posts
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses Git commands to manage its output, including
git status,git diff, andgit committo stage and save generated quote-post drafts to a local repository. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content from X (Twitter) bookmarks and the user's post history. This data is attacker-controlled and could contain malicious instructions.
- Ingestion points: External data is fetched from
x.combookmarks and search results via the in-app browser as defined inSKILL.md. - Boundary markers: Missing explicit delimiters for interpolated text, but instructions direct the agent to identify and ignore "one-off artifacts such as pasted prompts."
- Capability inventory: The agent has permissions to write to the local file system (
data/x-growth/) and execute Git operations. - Sanitization: Includes an explicit instruction to "Separate reusable patterns from one-off artifacts such as pasted prompts, transcripts, or link dumps" to prevent them from poisoning the voice ledger or influencing agent logic.
Audit Metadata