last30days

Warn

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill extracts session cookies for X/Twitter and Truth Social directly from browser SQLite databases including Chrome, Brave, Firefox, and Safari. It also includes logic to retrieve secrets from the macOS Keychain and the Linux 'pass' password manager.
  • [COMMAND_EXECUTION]: The skill invokes numerous external binaries via subprocess, such as yt-dlp for media processing, ffmpeg for transcription, and npx for installing Printing Press CLI tools.
  • [DATA_EXFILTRATION]: Research reports can be uploaded to the external service ht-ml.app for sharing. Additionally, search queries are sent to a remote API if hosted mode is configured.
  • [PROMPT_INJECTION]: Instructions in the skill attempt to conceal engine actions and tool usage from the user, which can be leveraged to hide the execution of sensitive local operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests large amounts of untrusted data from Reddit, X, and the general web, creating an expansive surface for potential indirect injection attacks despite the use of safety fencing.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 4, 2026, 01:16 PM
Security Audit — agent-trust-hub — last30days