tweet-insight

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches and processes content from untrusted external sources, which could contain malicious instructions designed to override agent behavior.
  • Ingestion points: The agent ingests data from external URLs via browser_navigate and browser_snapshot (Step 1) and WebFetch (Step 2).
  • Boundary markers: There are no instructions defining boundary markers or explicit prompts to the agent to ignore instructions embedded within the fetched content.
  • Capability inventory: The skill has the ability to navigate the web, fetch snapshots, and invoke the personal-chinese-writing-style skill.
  • Sanitization: No sanitization or validation mechanisms are described to filter out potential injection patterns in the fetched text.
  • [COMMAND_EXECUTION]: The skill utilizes Playwright MCP tools such as browser_navigate and browser_snapshot to interact with and extract data from live web pages.
  • [EXTERNAL_DOWNLOADS]: The skill makes network requests to r.jina.ai, which is a well-known service used for web content extraction and RAG (Retrieval-Augmented Generation) workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 07:41 AM
Security Audit — agent-trust-hub — tweet-insight