twitter-thread-creation

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or security vulnerabilities were detected. The skill's operations are consistent with its stated purpose of social media content creation.\n- [COMMAND_EXECUTION]: Orchestrates the use of the infsh CLI to post tweets via x/post-create, generate media using infsh/html-to-image, and capture screenshots with infsh/agent-browser.\n- [EXTERNAL_DOWNLOADS]: References the installation of additional verified skill packages from the inference-sh registry using the npx package runner, which is a trusted vendor source.\n- [PROMPT_INJECTION]: Identifies an indirect prompt injection surface (Ingestion points: Tavily search results and web browser content; Boundary markers: JSON-encoded tool inputs; Capability inventory: Twitter posting and media generation via infsh; Sanitization: Handled by the underlying vendor tool APIs).
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 05:41 PM