Audit History
twitter-automation - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 12, 2026, 10:22 AM | 2 confirmed | 15 | No capability change |
| v4 | Jul 12, 2026, 10:22 AM | 2 confirmed | 15 | No capability change |
| v3 | Jul 8, 2026, 02:06 PM | 2 confirmed | 16 | No capability change |
| v2 | Jul 9, 2026, 11:51 AM | 2 confirmed | 15 | No capability change |
| v1 | Jul 8, 2026, 02:06 PM | 2 confirmed | 16 | Baseline |
Jul 12, 2026, 10:22 AM
The skill intentionally runs belt and npx commands, including authenticated Twitter/X actions and third-party skill installation. Markdown formatting and ordinary documentation links are false positives, but the remote image, unpinned installs, and missing action confirmations remain real risks.
Confirmed security concerns (2)
Capability review items (15)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (37)
🌐 Network access (7)
Jul 12, 2026, 10:22 AM
The skill intentionally runs belt and npx commands, including authenticated Twitter/X actions and third-party skill installation. Markdown formatting and ordinary documentation links are false positives, but the remote image, unpinned installs, and missing action confirmations remain real risks.
Confirmed security concerns (2)
Capability review items (15)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (37)
🌐 Network access (7)
Jul 8, 2026, 02:06 PM
The skill is documentation-only, but it includes actionable belt and npx commands for installing external skills and performing authenticated Twitter/X actions. I confirmed real command-execution and account-mutation examples, while marking markdown fences, app identifiers, and ordinary documentation links as false positives. No prompt injection text was found.
Confirmed security concerns (2)
Capability review items (16)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (37)
🌐 Network access (7)
Jul 9, 2026, 11:51 AM
The static backtick detector produced many Markdown false positives; most table entries, code fences, and documentation links are not executable code. Risk remains because belt CLI commands can post, delete, DM, follow, like, and retweet through a connected X account. No prompt injection language was found in SKILL.md.
Confirmed security concerns (2)
Capability review items (15)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (37)
🌐 Network access (7)
Jul 8, 2026, 02:06 PM
The skill is documentation-only, but it includes actionable belt and npx commands for installing external skills and performing authenticated Twitter/X actions. I confirmed real command-execution and account-mutation examples, while marking markdown fences, app identifiers, and ordinary documentation links as false positives. No prompt injection text was found.
Confirmed security concerns (2)
Capability review items (16)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.