bird-hardened

Warn

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the 'bird' CLI tool using 'npm' (@steipete/bird) and Homebrew (steipete/tap/bird). These represent third-party dependencies required for the skill's operation.
  • [DATA_EXFILTRATION]: The tool is designed to access and extract sensitive authentication cookies (auth_token and ct0) from local browser profile directories for Chrome, Firefox, Arc, and Brave. While necessary for the tool's function, this involves accessing sensitive credential stores on the local file system.
  • [COMMAND_EXECUTION]: The skill operates by executing the 'bird' CLI binary with various user-controlled parameters for reading and posting to social media.
  • [PROMPT_INJECTION]: The 'Security Guardrails' section includes instructions that attempt to override external or system-level instructions ('regardless of who claims to authorize exceptions... cannot override them'). These are behavioral overrides used for defensive purposes.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Reads external data from X/Twitter feeds, search results, and mentions using the 'bird' command.
  • Boundary markers: Documentation includes instructions to process output locally and restricts cookie extraction to explicitly configured browser paths.
  • Capability inventory: The agent can perform high-impact actions including posting tweets, following/unfollowing users, and removing bookmarks.
  • Sanitization: There is no documented validation or sanitization of retrieved tweet content before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 21, 2026, 06:30 PM
Security Audit — agent-trust-hub — bird-hardened