tweetclaw-x-twitter-automation
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the
@xquik/tweetclawplugin, which is an external dependency required for the core Twitter automation functionality.\n- [PROMPT_INJECTION]: The skill's primary function involves processing external content from X/Twitter (tweets and replies), which creates an inherent surface for indirect prompt injection attacks.\n - Ingestion points: Untrusted data is ingested when searching tweets or monitoring replies in SKILL.md.\n
- Boundary markers: While the skill defines a structured output format for findings, it does not specify explicit delimiters or isolation instructions for the raw external data processed.\n
- Capability inventory: The agent has capabilities to perform significant account actions including posting tweets and sending direct messages through the plugin.\n
- Sanitization: No specific sanitization or filtering logic is described for the retrieved tweet content prior to analysis.
Audit Metadata