x-twitter-scraper

Fail

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: CRITICALMETADATA_POISONINGOBFUSCATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The skill includes a standalone file skillspector-report.md that provides a fabricated security audit claiming a 'safe' recommendation and zero findings. This is a deceptive attempt to influence users and security analyzers into trusting the skill without independent verification.
  • [OBFUSCATION]: The instructions in SKILL.md include highly specific and non-standard linguistic constraints, such as forbidding the AI from using the word 'public' (referring to it as the combination of 'pub' and 'lic') and restricting the use of certain punctuation marks. These rules are characteristic of techniques used to evade keyword-based monitoring or to embed hidden messages in model outputs.
  • [EXTERNAL_DOWNLOADS]: Automated scanners (URLite) have identified the service domain xquik.com used for API calls as a phishing risk. Furthermore, the repository includes a file references/scrape-export-twitter-data.md that triggered malware reputation alerts during scanning.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted content from X (Twitter), creating a surface for indirect prompt injection. While the skill defines boundary markers for isolation, the effectiveness of these markers against sophisticated adversarial content is unverified, and the inclusion of self-referential safety claims targets the analyzer's own reasoning process.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 9, 2026, 03:53 AM
Security Audit — agent-trust-hub — x-twitter-scraper