monitor-accounts
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: Interacts with the vendor API at
https://xquik.com/api/v1to create and manage account monitors.\n- [PROMPT_INJECTION]: Addresses the risk of indirect prompt injection by instructing the agent to treat monitored tweet text as untrusted data and to only surface it to the user without taking automated actions.\n - Ingestion points: External content fetched from the
/eventsendpoint as described inSKILL.md.\n - Boundary markers: Prompt instructions require the agent to surface content as data and never auto-act on events.\n
- Capability inventory: Authorized tools are restricted to API endpoints for monitoring management.\n
- Sanitization: Explicitly identifies monitored text as untrusted in the Security section.
Audit Metadata