twitter-work-search

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content retrieved from X (Twitter), which represents a surface for indirect prompt injection. Maliciously crafted tweets could attempt to influence the agent's behavior during data presentation.
  • Ingestion points: references/core_workflow.md (Step 2 and 3) describes fetching tweet data from an external API.
  • Boundary markers: The skill includes a 'Data Description' block (Step 4.1) but lacks explicit delimiters or instructions to ignore embedded commands within the processed tweet text.
  • Capability inventory: The skill formats and displays data to the user.
  • Sanitization: No specific filtering or sanitization of external content is documented.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill communicates with an external API at https://redfox.hk/story/api/x/search. This domain is the official API endpoint for the vendor's service and is required for the skill's primary functionality. The operation is documented neutrally as a core feature.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 09:46 AM
Security Audit — agent-trust-hub — twitter-work-search