twitter

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes arbitrary tweet content from external sources, creating a surface for indirect prompt injection attacks.
  • Ingestion points: The x-search/x-search.ts script and x-search/lib/api.ts library ingest tweet data from the official X API and the bird CLI.
  • Boundary markers: While the x-search/lib/format.ts script uses Markdown blockquotes to delineate tweet text, it does not provide explicit instructions to the agent to disregard potentially malicious instructions embedded in the external data.
  • Capability inventory: The skill has the capability to execute local shell commands (via Bun.spawn), perform network requests (via fetch), and write files to the research and cache directories.
  • Sanitization: Tweet data is formatted for display but does not undergo rigorous sanitization or escaping to strip potential prompt injection payloads from the tweet body.
  • [EXTERNAL_DOWNLOADS]: The documentation (README.md and SKILL.md) suggests installing the bird CLI from an unofficial repository mirror (github.com/LaceLetho/bird-cli-backup) because the original source repository was deleted by its author. Relying on unofficial mirrors for executable tools presents a supply chain risk.
  • [COMMAND_EXECUTION]: The skill uses Bun.spawn in x-search/x-search.ts to execute the bird CLI locally and capture its output for processing, which executes logic from the externally installed package.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 01:58 AM
Security Audit — agent-trust-hub — twitter