soia-pkm-clip-x-profile
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection surface identified through the ingestion of untrusted external content. * Ingestion points: The
scripts/profile_x.pyscript retrieves post text and image descriptions from the publicapi.fxtwitter.comAPI. * Boundary markers: Harvested data is structured in Markdown files using headers (e.g.,## Source prompt evidence), but the skill lacks explicit delimiters or instructions to the AI to ignore instructions embedded within the harvested text. * Capability inventory: The skill is designed to perform network requests for data retrieval and write findings to the local file system. It does not execute dynamic code or shell commands based on input. * Sanitization: Text is normalized for display but is not sanitized to remove or neutralize potential LLM-targeting instructions embedded in the social media content. - [EXTERNAL_DOWNLOADS]: The skill connects to
api.fxtwitter.comto retrieve status updates and profile metadata. This network activity is the primary functional requirement for its stated purpose of social media research.
Audit Metadata