mktg-x

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill incorporates a library for extracting session cookies from local browsers (Chrome, Edge, Firefox, and Safari). This process involves calling standard system utilities—such as 'security' on macOS, 'powershell' on Windows, or 'secret-tool' on Linux—to retrieve the necessary decryption keys from the user's system keyring. These operations are scoped strictly to the authentication discovery process.
  • [EXTERNAL_DOWNLOADS]: To maintain functionality with X's internal API, the skill automatically fetches official JavaScript bundles from X's content delivery network (abs.twimg.com). This is used to dynamically identify rotated GraphQL query IDs and is a standard requirement for maintaining unauthorized API clients.
  • [PROMPT_INJECTION]: The skill contains comprehensive documentation regarding indirect prompt injection risks. It specifically instructs the agent to treat all data retrieved from X as untrusted content and provides clear guidelines to ignore any instructions or overrides that may be present within tweet text.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 02:06 PM
Security Audit — agent-trust-hub — mktg-x