social-x-post-card
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's HTML template fetches styling and typography resources from well-known and reputable services. Specifically, it loads the Tailwind CSS framework from
cdn.tailwindcss.comand fonts from Google'sfonts.googleapis.com. These are standard practices for web development and do not involve untrusted remote code execution. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied text and metrics to populate the HTML card. While this represents a surface for processing external data, the skill's instructions include safety boundaries such as 'cannot fabricate tweets' and 'content must come from user input,' which mitigates the risk of the agent being misled by the data it is rendering.
Audit Metadata