social-bridge

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run in social_bridge/twitter.py to interact with the surf CLI for browser automation. These calls are used to navigate X/Twitter, scroll pages, and extract text. The inputs (account names) are normalized, and the commands are executed as a list of arguments rather than a shell string, which is a secure practice for subprocess invocation.
  • [EXTERNAL_DOWNLOADS]: The skill fetches data from external social media platforms, specifically public Telegram channels via the Telethon library and X/Twitter accounts via browser automation. These operations are core to the skill's purpose as an aggregator.
  • [DATA_EXFILTRATION]: Aggregated content is forwarded to Discord webhooks as configured by the user. While this involves sending data to an external service, it is a primary, documented feature of the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from social media feeds. It implements a security tagging system in social_bridge/utils.py using regex patterns to categorize posts. While it processes external data, the current implementation does not dynamically execute instructions found within that data.
  • [PRIVILEGE_ESCALATION]: No evidence of privilege escalation (e.g., sudo, chmod 777) was found. The skill operates within the user's home directory (~/.social-bridge) and communicates with a local memory service via a Unix domain socket.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — social-bridge