soia-pkm-clip-x-profile

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection surface identified through the ingestion of untrusted external content. * Ingestion points: The scripts/profile_x.py script retrieves post text and image descriptions from the public api.fxtwitter.com API. * Boundary markers: Harvested data is structured in Markdown files using headers (e.g., ## Source prompt evidence), but the skill lacks explicit delimiters or instructions to the AI to ignore instructions embedded within the harvested text. * Capability inventory: The skill is designed to perform network requests for data retrieval and write findings to the local file system. It does not execute dynamic code or shell commands based on input. * Sanitization: Text is normalized for display but is not sanitized to remove or neutralize potential LLM-targeting instructions embedded in the social media content.
  • [EXTERNAL_DOWNLOADS]: The skill connects to api.fxtwitter.com to retrieve status updates and profile metadata. This network activity is the primary functional requirement for its stated purpose of social media research.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 08:07 AM
Security Audit — agent-trust-hub — soia-pkm-clip-x-profile