twitter-reader
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves post content from Twitter/X which is processed by the agent. This content is untrusted and could contain hidden instructions or malicious prompts designed to influence the agent's behavior.
- Ingestion points: The scripts
scripts/fetch_tweet.pyandscripts/fetch_tweets.shingest data from an external source (Twitter via Jina.ai). - Boundary markers: The skill does not implement delimiters or 'ignore' instructions to wrap the fetched content.
- Capability inventory: The skill has the capability to write the fetched data to the local file system using
Path(output_file).write_textinscripts/fetch_tweet.py. - Sanitization: No sanitization or filtering of the fetched content is performed before it is output to the user or saved to a file.
- [COMMAND_EXECUTION]: The skill executes external commands via the shell and Python subprocesses.
scripts/fetch_tweet.pyusessubprocess.run()with a list of arguments to callcurl, which is a safe practice that prevents shell injection.scripts/fetch_tweets.shexecutescurldirectly but includes regex validation (^https?://(x\.com|twitter\.com)/) to ensure input URLs are restricted to specific domains.- [EXTERNAL_DOWNLOADS]: The skill fetches content from the Jina.ai Reader API (
r.jina.ai). This is a well-known service for converting web pages to markdown for AI consumption.
Audit Metadata