threat-intelligence

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides shell commands to execute local setup scripts (bootstrap-reverse.ps1 and bootstrap-reverse.sh) to initialize MCP capabilities. The PowerShell command uses the '-ExecutionPolicy Bypass' flag to ignore local script signing policies.
  • [EXTERNAL_DOWNLOADS]: The skill depends on xquik.com, a third-party service for cyber threat intelligence. It instructs the agent to register a remote endpoint (https://xquik.com/mcp) as an MCP host to enable X/Twitter search functionality.
  • [PROMPT_INJECTION]: The skill processes untrusted external data from X/Twitter, creating a surface for indirect prompt injection. Ingestion points: Public posts are retrieved via the Xquik API for analysis (SKILL.md, Section 3). Boundary markers: The workflow mandates wrapping external content in <UNTRUSTED_PUBLIC_SOURCE> tags to prevent the agent from executing embedded instructions (SKILL.md, Section 3). Capability inventory: The agent is authorized to execute shell commands and read files from parent directories. Sanitization: The skill outlines normalization and validation steps for extracted IOCs to filter malicious or malformed inputs (references/x-public-intelligence.md).
  • [DATA_EXFILTRATION]: The workflow requires accessing configuration and precedent files located in parent directories (../ops/scope-contract.md and ../field-journal/precedent-pentest.md), which may contain sensitive project scope information.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 09:08 AM
Security Audit — agent-trust-hub — threat-intelligence