tweetclaw-source-research

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @xquik/tweetclaw plugin from the NPM registry to function.
  • [COMMAND_EXECUTION]: The skill uses the openclaw CLI for plugin management, inspection, and runtime tracing.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from X (tweets, replies, and profile information). While the instructions specifically warn the agent not to follow commands embedded in this external content, the data ingestion remains an inherent attack surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:56 AM
Security Audit — agent-trust-hub — tweetclaw-source-research