Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes arbitrary tweet content from external sources, creating a surface for indirect prompt injection attacks.
- Ingestion points: The
x-search/x-search.tsscript andx-search/lib/api.tslibrary ingest tweet data from the official X API and thebirdCLI. - Boundary markers: While the
x-search/lib/format.tsscript uses Markdown blockquotes to delineate tweet text, it does not provide explicit instructions to the agent to disregard potentially malicious instructions embedded in the external data. - Capability inventory: The skill has the capability to execute local shell commands (via
Bun.spawn), perform network requests (viafetch), and write files to the research and cache directories. - Sanitization: Tweet data is formatted for display but does not undergo rigorous sanitization or escaping to strip potential prompt injection payloads from the tweet body.
- [EXTERNAL_DOWNLOADS]: The documentation (
README.mdandSKILL.md) suggests installing thebirdCLI from an unofficial repository mirror (github.com/LaceLetho/bird-cli-backup) because the original source repository was deleted by its author. Relying on unofficial mirrors for executable tools presents a supply chain risk. - [COMMAND_EXECUTION]: The skill uses
Bun.spawninx-search/x-search.tsto execute thebirdCLI locally and capture its output for processing, which executes logic from the externally installed package.
Audit Metadata