x-api
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources including X mentions, search results, and long-form articles. This creates a vulnerability where malicious instructions embedded in tweets could influence the agent's behavior.
- Ingestion points: Fetches data from
api.twitter.comandapi.x.comendpoints, including mentions, timeline tweets, search results, and article text extracted viaagent-browser. - Boundary markers: The skill suggests separating root posts from "Reply signals" in notes, which provides some context separation but lacks formal security delimiters (like XML tags or clear 'ignore' instructions) for the agent when processing the raw text.
- Capability inventory: The skill can post new tweets, reply to existing tweets, delete tweets, and follow users. It also has the capability to execute shell commands and Python scripts within the agent environment.
- Sanitization: There is no mention of sanitization, escaping, or filtering of the ingested tweet content before it is processed by the agent.
- [DYNAMIC_EXECUTION]: The skill uses Python heredocs and runtime script generation to handle complex logic.
- Evidence: Authentication flows for deriving bearer tokens and signing OAuth 1.0a requests are implemented via inline Python scripts (
python3 <<'PY'). - Evidence: Uses
uv run --with requests-oauthlibto dynamically load dependencies and execute scripts. - [COMMAND_EXECUTION]: The skill executes local shell commands to perform its primary functions.
- Evidence: Uses
curlfor direct API calls to X endpoints. - Evidence: Uses
secrets leaseandsecrets revoketo manage API credentials securely during runtime. - [EXTERNAL_DOWNLOADS]: The skill downloads an external library at runtime to support its operations.
- Evidence: Fetches the
requests-oauthlibpackage from the standard Python package registry usinguv. This is a well-known library used for the intended purpose of request signing.
Audit Metadata