xurl
Fail
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The installation instructions recommend executing a remote shell script using 'curl -fsSL https://raw.githubusercontent.com/xdevplatform/xurl/main/install.sh | bash'. This pattern allows for arbitrary, unverified code execution from a third-party repository on the user's machine, representing a severe security risk.- [EXTERNAL_DOWNLOADS]: The skill relies on external binary distributions (Homebrew, npm, and shell scripts) from the 'xdevplatform' GitHub organization. This source is not recognized as a trusted organization or well-known service and does not align with the established vendor patterns for the skill author (Liberty-Emporium).- [DATA_EXFILTRATION]: The skill explicitly interacts with and references the '~/.xurl' file, which serves as a local database for sensitive OAuth credentials and bearer tokens. Accessing such sensitive file paths, combined with the usage of network-capable tools, creates a significant risk of credential exposure.- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the ingestion of untrusted content from the X (Twitter) API.
- Ingestion points: Data retrieved via 'xurl search', 'xurl mentions', 'xurl read', and 'xurl dms'.
- Boundary markers: Absent; the instructions do not provide delimiters or warnings for the agent to ignore instructions embedded in API responses.
- Capability inventory: The skill provides extensive write access to the X API (post, delete, follow, DM) which can be abused if the agent obeys instructions found in processed posts.
- Sanitization: Absent; no sanitization or validation of the API output is performed before it is processed by the agent.- [COMMAND_EXECUTION]: The skill's primary functionality is built around the execution of the 'xurl' CLI tool, allowing the agent to run arbitrary shell commands with complex arguments, including raw API requests and media file uploads.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/xdevplatform/xurl/main/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata