x-twitter-scraper
Warn
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill instructions require the user to execute
npx skills@1.5.3 add Xquik-dev/x-twitter-scraper, which downloads and adds code from theXquik-devGitHub organization. This source is not a verified or trusted vendor, posing a supply chain risk through the installation of unverified external components. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from X (Twitter), which is an untrusted external source. This creates a surface for indirect prompt injection where malicious instructions could be embedded in tweets, profiles, or metadata. 1. Ingestion points: X/Twitter posts, profiles, media, and search results (SKILL.md). 2. Boundary markers: The instructions include a specific warning to treat retrieved content as untrusted data and to not follow instructions embedded in retrieved posts. 3. Capability inventory: Tool access for tweet search, profile history, and data export. 4. Sanitization: The instructions specify that retrieved content should be quoted or summarized only as data.
Audit Metadata