twitter-reader

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves post content from Twitter/X which is processed by the agent. This content is untrusted and could contain hidden instructions or malicious prompts designed to influence the agent's behavior.
  • Ingestion points: The scripts scripts/fetch_tweet.py and scripts/fetch_tweets.sh ingest data from an external source (Twitter via Jina.ai).
  • Boundary markers: The skill does not implement delimiters or 'ignore' instructions to wrap the fetched content.
  • Capability inventory: The skill has the capability to write the fetched data to the local file system using Path(output_file).write_text in scripts/fetch_tweet.py.
  • Sanitization: No sanitization or filtering of the fetched content is performed before it is output to the user or saved to a file.
  • [COMMAND_EXECUTION]: The skill executes external commands via the shell and Python subprocesses.
  • scripts/fetch_tweet.py uses subprocess.run() with a list of arguments to call curl, which is a safe practice that prevents shell injection.
  • scripts/fetch_tweets.sh executes curl directly but includes regex validation (^https?://(x\.com|twitter\.com)/) to ensure input URLs are restricted to specific domains.
  • [EXTERNAL_DOWNLOADS]: The skill fetches content from the Jina.ai Reader API (r.jina.ai). This is a well-known service for converting web pages to markdown for AI consumption.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:03 AM
Security Audit — agent-trust-hub — twitter-reader