social-bridge
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.runinsocial_bridge/twitter.pyto interact with thesurfCLI for browser automation. These calls are used to navigate X/Twitter, scroll pages, and extract text. The inputs (account names) are normalized, and the commands are executed as a list of arguments rather than a shell string, which is a secure practice for subprocess invocation. - [EXTERNAL_DOWNLOADS]: The skill fetches data from external social media platforms, specifically public Telegram channels via the Telethon library and X/Twitter accounts via browser automation. These operations are core to the skill's purpose as an aggregator.
- [DATA_EXFILTRATION]: Aggregated content is forwarded to Discord webhooks as configured by the user. While this involves sending data to an external service, it is a primary, documented feature of the skill.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from social media feeds. It implements a security tagging system in
social_bridge/utils.pyusing regex patterns to categorize posts. While it processes external data, the current implementation does not dynamically execute instructions found within that data. - [PRIVILEGE_ESCALATION]: No evidence of privilege escalation (e.g., sudo, chmod 777) was found. The skill operates within the user's home directory (
~/.social-bridge) and communicates with a local memory service via a Unix domain socket.
Audit Metadata