twitter-thread-creation

Warn

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an external installation script at https://raw.githubusercontent.com/inference-sh/skills/refs/heads/main/cli-install.md and instructs the installation of the belt-sh/cli package via npx. These sources are not recognized as trusted vendors.\n- [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands through the belt CLI, including authentication (belt login) and running specific application modules (belt app run).\n- [PROMPT_INJECTION]: The skill contains ingestion points for untrusted data that could lead to indirect prompt injection.\n
  • Ingestion points: Web content accessed via infsh/agent-browser and search results from tavily/search-assistant.\n
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands were found in the skill text.\n
  • Capability inventory: The skill allows the agent to post to social media, browse the web, and execute scoped bash commands.\n
  • Sanitization: No input validation or output sanitization mechanisms are described for handling fetched data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 7, 2026, 06:32 PM
Security Audit — agent-trust-hub — twitter-thread-creation