x-publish
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/copy_to_clipboard.pyscript usessubprocess.Popento interact with Linux clipboard utilities (xcliporxsel). The implementation securely passes arguments as a list and transfers data via standard input pipes, avoiding shell injection risks. - [EXTERNAL_DOWNLOADS]: The skill instructions specify the installation of standard third-party libraries such as
Pillow,pyobjc-framework-Cocoa,pywin32, andpyperclipfor system and browser integration. These are well-known packages for cross-platform support. - [COMMAND_EXECUTION]: The skill attempts to call an external telemetry script (
~/.claude/skills/x-create/scripts/x_state.py) to record publishing events. This establishes a dependency on the existence and specific path of another skill on the host system. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user content for posting, which presents a surface for indirect instructions. 1. Ingestion points: Untrusted text is received through command-line arguments and temporary files (
/tmp/tweet.txt). 2. Boundary markers: The instructions do not define delimiters or specific warnings for the agent to ignore instructions embedded within the tweet content. 3. Capability inventory: The skill has the ability to write to the system clipboard, automate browser actions on X.com, and execute local scripts. 4. Sanitization: No explicit sanitization or escaping of the user content is performed before it is processed.
Audit Metadata