alphai-twitter

Pass

Audited by Gen Agent Trust Hub on Mar 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection risks as its primary purpose is to fetch and process user-generated content from X (Twitter).\n
  • Ingestion points: Untrusted data enters the agent context through several endpoints, including /tracker/x/monitorList, /x/search, and /x/tweets, as well as via real-time WebSocket streams.\n
  • Boundary markers: No specific boundary markers or instructions to ignore embedded commands are implemented to isolate tweet content from system instructions.\n
  • Capability inventory: The skill has no capabilities to execute local commands, write to the file system, or access sensitive local data. Network operations are restricted to the vendor's verified domains (b.alph.ai and ws.alph.ai).\n
  • Sanitization: No sanitization, filtering, or escaping of tweet content is performed before the data is returned for analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 16, 2026, 03:58 PM