tweet-insight
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill fetches and processes content from untrusted external sources, which could contain malicious instructions designed to override agent behavior.
- Ingestion points: The agent ingests data from external URLs via
browser_navigateandbrowser_snapshot(Step 1) andWebFetch(Step 2). - Boundary markers: There are no instructions defining boundary markers or explicit prompts to the agent to ignore instructions embedded within the fetched content.
- Capability inventory: The skill has the ability to navigate the web, fetch snapshots, and invoke the
personal-chinese-writing-styleskill. - Sanitization: No sanitization or validation mechanisms are described to filter out potential injection patterns in the fetched text.
- [COMMAND_EXECUTION]: The skill utilizes Playwright MCP tools such as
browser_navigateandbrowser_snapshotto interact with and extract data from live web pages. - [EXTERNAL_DOWNLOADS]: The skill makes network requests to
r.jina.ai, which is a well-known service used for web content extraction and RAG (Retrieval-Augmented Generation) workflows.
Audit Metadata