Warn
Audited by Snyk on Mar 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly fetches and processes public, user-generated tweets from X via the official x-search API and the session-based bird CLI (see SKILL.md "x-search — Official API Research" plus x-search/lib/api.ts and x-search/x-search.ts where api.search/profile/thread/getTweet are called and results are formatted/synthesized), so untrusted third-party content is ingested and used to drive research, synthesis, and follow-up actions.
Audit Metadata