x-cdp-api
Warn
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use the 'evaluate_script' tool to execute JavaScript within an active browser tab, allowing it to perform authenticated actions on X (Twitter). This includes logic to bypass platform-enforced rate limits by using specific delays and chunked request patterns.
- [CREDENTIALS_UNSAFE]: The script contains a hardcoded Bearer token and instructions to extract the 'ct0' CSRF token from browser cookies ('document.cookie'). This enables the agent to perform actions using the user's active session authentication without direct user involvement for each request.
Audit Metadata