Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONINGDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from Twitter/X which may contain malicious instructions designed to manipulate the agent. 1. Ingestion points: Data is fetched in client.py via proxied_get. 2. Boundary markers: Absent; the skill does not use delimiters to isolate external data. 3. Capability inventory: The skill performs read-only network operations via a controlled proxy; it does not contain direct file-write or shell-execution logic. 4. Sanitization: Absent; external data is returned as raw dictionary structures.
- [METADATA_POISONING]: A version mismatch was detected between the skill metadata in SKILL.md (v2.0.2) and the extension information in init.py (v1.1.0), which may cause confusion regarding current capabilities.
- [DYNAMIC_EXECUTION]: The skill instructions in SKILL.md require the agent to generate and run Python code via a bash block, which constitutes dynamic script generation and execution from provided templates.
Audit Metadata