dsh-x
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes untrusted data from X (Twitter) via a proxy API, which could contain malicious instructions designed to subvert the agent's behavior.
- Ingestion points: Untrusted data is ingested through the
scripts/dsh_x.pyscript via the/api/search,/api/user, and/api/threadendpoints, which return X posts, threads, and image descriptions. - Boundary markers: The instructions in
SKILL.mdlack explicit delimiters or instructions to the agent to ignore embedded commands within the retrieved content. In fact, it explicitly instructs the agent to "Relay permalinks and quoted text verbatim," which increases the risk of the agent obeying instructions hidden in social media posts. - Capability inventory: The script performs network operations (HTTP GET/POST) to a user-configured API endpoint and manages a local configuration file at
~/.config/dsh-x/config.jsonwith restricted permissions. It does not spawn other subprocesses. - Sanitization: The client-side script does not perform sanitization, filtering, or escaping of the content returned by the API; it presents the data directly to the agent.
Audit Metadata