xquik-x-data
Fail
Audited by Gen Agent Trust Hub on Jul 26, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references documentation at
docs.xquik.com, which has been flagged as malicious by automated security scanners. This poses a significant risk of malware infection, drive-by downloads, or phishing if the agent or user accesses these sites. - [DATA_EXFILTRATION]: The skill manages X/Twitter API keys and data retrieval workflows. Directing these sensitive operations through a service whose documentation infrastructure is flagged as malicious creates a high risk of credential harvesting or unauthorized data exposure.
- [COMMAND_EXECUTION]: The skill allows the use of the
Bashtool and references an external GitHub repository (github.com/Xquik-dev/x-twitter-scraper). Instructions that guide the agent to interact with or execute code from unverified external sources linked to flagged domains increase the risk of arbitrary command execution on the host system. - [PROMPT_INJECTION]: There is a discrepancy between the author listed in the metadata (
xquik) and the actual author identity (MKAbuMattar). This deceptive metadata can mislead users regarding the skill's origin and safety. Furthermore, the skill processes untrusted data from X/Twitter (Ingestion Point: X/Twitter API) and possesses high-privilege capabilities (Bash,Write,WebFetch) without explicit boundary markers or sanitization logic, creating a surface for indirect prompt injection if external data or flagged documentation contains adversarial instructions.
Recommendations
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata