Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill communicates with the external service
api.twitterapi.ioto fetch Twitter data. This is the primary function of the skill and uses standard API request patterns via the Python standard library. - [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes untrusted content from Twitter, such as tweet text, user biographies, and article content, which could contain instructions designed to influence the AI agent's behavior.
- Ingestion points: Data is fetched from the network in
scripts/twitter_api.pyand returned to the agent. - Boundary markers: None present; the skill returns raw or truncated text directly.
- Capability inventory: The skill does not possess dangerous capabilities such as file system writing, privilege escalation, or arbitrary code execution.
- Sanitization: Content is formatted for display but does not undergo specific sanitization to remove potential prompt injection sequences.
Audit Metadata