x-api
Warn
Audited by Snyk on Apr 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly calls the X/Twitter API to "read timelines" and "search X" and includes commands like
python3 $HOME/.claude/scripts/x-api-poster.py read-timelinein SKILL.md, so it fetches and ingests public, user-generated social-media content that the agent may read and act on.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata