x-bookmark-quote-posts

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses Git commands to manage its output, including git status, git diff, and git commit to stage and save generated quote-post drafts to a local repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content from X (Twitter) bookmarks and the user's post history. This data is attacker-controlled and could contain malicious instructions.
  • Ingestion points: External data is fetched from x.com bookmarks and search results via the in-app browser as defined in SKILL.md.
  • Boundary markers: Missing explicit delimiters for interpolated text, but instructions direct the agent to identify and ignore "one-off artifacts such as pasted prompts."
  • Capability inventory: The agent has permissions to write to the local file system (data/x-growth/) and execute Git operations.
  • Sanitization: Includes an explicit instruction to "Separate reusable patterns from one-off artifacts such as pasted prompts, transcripts, or link dumps" to prevent them from poisoning the voice ledger or influencing agent logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 07:31 AM
Security Audit — agent-trust-hub — x-bookmark-quote-posts