xai
Warn
Audited by Snyk on Mar 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's scripts/search-x.js explicitly calls the xAI Responses API with the x_search tool to fetch real, user-generated X/Twitter posts (and then parses and acts on those tweets/citations), exposing the agent to untrusted third-party content from X/Twitter.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata