skills/loadchange/dsh-x-search/dsh-x/Gen Agent Trust Hub

dsh-x

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes untrusted data from X (Twitter) via a proxy API, which could contain malicious instructions designed to subvert the agent's behavior.
  • Ingestion points: Untrusted data is ingested through the scripts/dsh_x.py script via the /api/search, /api/user, and /api/thread endpoints, which return X posts, threads, and image descriptions.
  • Boundary markers: The instructions in SKILL.md lack explicit delimiters or instructions to the agent to ignore embedded commands within the retrieved content. In fact, it explicitly instructs the agent to "Relay permalinks and quoted text verbatim," which increases the risk of the agent obeying instructions hidden in social media posts.
  • Capability inventory: The script performs network operations (HTTP GET/POST) to a user-configured API endpoint and manages a local configuration file at ~/.config/dsh-x/config.json with restricted permissions. It does not spawn other subprocesses.
  • Sanitization: The client-side script does not perform sanitization, filtering, or escaping of the content returned by the API; it presents the data directly to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:07 PM