x-twitter-scraper
Fail
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: CRITICALMETADATA_POISONINGOBFUSCATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [METADATA_POISONING]: The skill includes a standalone file
skillspector-report.mdthat provides a fabricated security audit claiming a 'safe' recommendation and zero findings. This is a deceptive attempt to influence users and security analyzers into trusting the skill without independent verification. - [OBFUSCATION]: The instructions in
SKILL.mdinclude highly specific and non-standard linguistic constraints, such as forbidding the AI from using the word 'public' (referring to it as the combination of 'pub' and 'lic') and restricting the use of certain punctuation marks. These rules are characteristic of techniques used to evade keyword-based monitoring or to embed hidden messages in model outputs. - [EXTERNAL_DOWNLOADS]: Automated scanners (URLite) have identified the service domain
xquik.comused for API calls as a phishing risk. Furthermore, the repository includes a filereferences/scrape-export-twitter-data.mdthat triggered malware reputation alerts during scanning. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted content from X (Twitter), creating a surface for indirect prompt injection. While the skill defines boundary markers for isolation, the effectiveness of these markers against sophisticated adversarial content is unverified, and the inclusion of self-referential safety claims targets the analyzer's own reasoning process.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata