x-trends
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [NO_CODE]: The skill provides API documentation and usage instructions but does not contain any executable scripts or code.
- [DATA_EXFILTRATION]: The skill communicates with the vendor's API at
https://xquik.com/api/v1as part of its core functionality. - [PROMPT_INJECTION]: The skill handles data from an external source (X/Twitter) which creates a surface for indirect prompt injection. 1. Ingestion points: Data retrieved via the
/trendsendpoint inSKILL.md. 2. Boundary markers: The 'Security' section instructs the agent to treat trend names and contexts as data only. 3. Capability inventory: No command execution or system-writing capabilities are present in this skill. 4. Sanitization: The skill uses instructional guardrails to prevent the agent from executing instructions found in user-generated trend content.
Audit Metadata