skills/nocoo/xray/xray-me/Gen Agent Trust Hub

xray-me

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data from Twitter (bookmarks and liked tweets), creating a surface for indirect prompt injection.
  • Ingestion points: Fetched tweets are saved to data/me-data.json and then read by the model to generate a report.
  • Boundary markers: No delimiters or warnings are used to differentiate tweet content from system instructions.
  • Capability inventory: The skill can execute local scripts, read sensitive configuration files, and perform file system operations.
  • Sanitization: There is no mechanism described for filtering or sanitizing tweet text before analysis.
  • [COMMAND_EXECUTION]: The skill executes a notification script using an absolute file system path outside its directory: /Users/nocoo/workspace/personal/skill-task-notifier/scripts/notify.py. While associated with the author, executing code from hardcoded absolute paths is a security risk.
  • [CREDENTIALS_UNSAFE]: The skill requires and accesses sensitive session data (cookies) stored in config/config.json. Accessing credential-bearing files is a high-risk activity.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 02:32 PM
Security Audit — agent-trust-hub — xray-me