x-twitter-scraper

Fail

Audited by Gen Agent Trust Hub on May 25, 2026

Risk Level: CRITICALDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill's base API endpoint (https://xquik.com/api/v1) and MCP endpoint are associated with a domain flagged as a phishing risk by automated scanners, posing a severe threat of credential harvesting or data theft.
  • [EXTERNAL_DOWNLOADS]: The skill installation and usage require downloading unverified code from GitHub and NPM registries (Xquik-dev/hermes-tweet, @xquik/tweetclaw), which introduces remote code execution risks into the agent environment.
  • [PROMPT_INJECTION]: The skill processes untrusted data from X (Twitter) and has capabilities to post content and send DMs, creating an indirect prompt injection surface. (1) Ingestion points: Retreives tweets, bios, and engagement metrics through tools like tweet_read. (2) Boundary markers: No explicit markers or ignore-instructions are used to isolate untrusted data. (3) Capability inventory: Includes network operations, plugin installations, and automated messaging/posting tools. (4) Sanitization: There is no evidence of input validation or content filtering for external social media data.
Recommendations
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
May 25, 2026, 04:51 PM
Security Audit — agent-trust-hub — x-twitter-scraper