xquik-data-cn
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a guide for using Xquik services (REST API, OpenAPI, MCP) and does not contain any executable code or malicious instructions.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The instructions explicitly forbid the agent from printing, saving, or repeating sensitive credentials like API keys or webhook secrets. No hardcoded secrets were found.
- [EXTERNAL_DOWNLOADS]: References to external URLs (docs.xquik.com, xquik.com) are limited to documentation, OpenAPI schemas, and MCP manifests, which are standard for defining service integrations.
- [INDIRECT_PROMPT_INJECTION]: The skill is intended to process external data from X/Twitter. While this constitutes an ingestion point for untrusted content, the skill lacks dangerous capabilities (like shell execution or system modification) that would allow such content to cause significant harm. The documentation encourages distinguishing between raw data and agent analysis, which acts as a basic boundary marker.
Audit Metadata