xquik-x-data

Fail

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references documentation at docs.xquik.com, which has been flagged as malicious by automated security scanners. This poses a significant risk of malware infection, drive-by downloads, or phishing if the agent or user accesses these sites.
  • [DATA_EXFILTRATION]: The skill manages X/Twitter API keys and data retrieval workflows. Directing these sensitive operations through a service whose documentation infrastructure is flagged as malicious creates a high risk of credential harvesting or unauthorized data exposure.
  • [COMMAND_EXECUTION]: The skill allows the use of the Bash tool and references an external GitHub repository (github.com/Xquik-dev/x-twitter-scraper). Instructions that guide the agent to interact with or execute code from unverified external sources linked to flagged domains increase the risk of arbitrary command execution on the host system.
  • [PROMPT_INJECTION]: There is a discrepancy between the author listed in the metadata (xquik) and the actual author identity (MKAbuMattar). This deceptive metadata can mislead users regarding the skill's origin and safety. Furthermore, the skill processes untrusted data from X/Twitter (Ingestion Point: X/Twitter API) and possesses high-privilege capabilities (Bash, Write, WebFetch) without explicit boundary markers or sanitization logic, creating a surface for indirect prompt injection if external data or flagged documentation contains adversarial instructions.
Recommendations
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 26, 2026, 02:37 PM
Security Audit — agent-trust-hub — xquik-x-data