xpoz-best-practices
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides official documentation and usage patterns for the Xpoz social media intelligence platform. All referenced tools and MCP endpoints (e.g., mcp.xpoz.ai) are owned by the vendor.
- [SAFE]: Recommended software dependencies, such as the 'xpoz' and 'xpoz-cli' Python packages and the '@xpoz/xpoz' Node.js package, are official libraries from the platform author.
- [SAFE]: Authentication procedures describe standard API key management and OAuth flows for the vendor's platform. The trial token retrieval method uses a legitimate vendor API endpoint (api.xpoz.ai).
- [SAFE]: No evidence of prompt injection, obfuscation, or malicious command execution was found. The skill's primary function is to facilitate the use of external social media data through the vendor's API.
Audit Metadata