x-publish

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/copy_to_clipboard.py script uses subprocess.Popen to interact with Linux clipboard utilities (xclip or xsel). The implementation securely passes arguments as a list and transfers data via standard input pipes, avoiding shell injection risks.
  • [EXTERNAL_DOWNLOADS]: The skill instructions specify the installation of standard third-party libraries such as Pillow, pyobjc-framework-Cocoa, pywin32, and pyperclip for system and browser integration. These are well-known packages for cross-platform support.
  • [COMMAND_EXECUTION]: The skill attempts to call an external telemetry script (~/.claude/skills/x-create/scripts/x_state.py) to record publishing events. This establishes a dependency on the existence and specific path of another skill on the host system.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user content for posting, which presents a surface for indirect instructions. 1. Ingestion points: Untrusted text is received through command-line arguments and temporary files (/tmp/tweet.txt). 2. Boundary markers: The instructions do not define delimiters or specific warnings for the agent to ignore instructions embedded within the tweet content. 3. Capability inventory: The skill has the ability to write to the system clipboard, automate browser actions on X.com, and execute local scripts. 4. Sanitization: No explicit sanitization or escaping of the user content is performed before it is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 07:35 AM