xray-me
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data from Twitter (bookmarks and liked tweets), creating a surface for indirect prompt injection.
- Ingestion points: Fetched tweets are saved to
data/me-data.jsonand then read by the model to generate a report. - Boundary markers: No delimiters or warnings are used to differentiate tweet content from system instructions.
- Capability inventory: The skill can execute local scripts, read sensitive configuration files, and perform file system operations.
- Sanitization: There is no mechanism described for filtering or sanitizing tweet text before analysis.
- [COMMAND_EXECUTION]: The skill executes a notification script using an absolute file system path outside its directory:
/Users/nocoo/workspace/personal/skill-task-notifier/scripts/notify.py. While associated with the author, executing code from hardcoded absolute paths is a security risk. - [CREDENTIALS_UNSAFE]: The skill requires and accesses sensitive session data (cookies) stored in
config/config.json. Accessing credential-bearing files is a high-risk activity.
Audit Metadata