baoyu-post-to-x
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: Orchestrates system interactions via
spawnandspawnSyncto manage clipboard data and simulate keystrokes using platform-specific tools likeosascript(macOS),powershell.exe(Windows), andxdotool(Linux). - [EXTERNAL_DOWNLOADS]: The
scripts/md-to-html.tsutility includes functionality to fetch remote images from external URLs during the Markdown conversion process. - [COMMAND_EXECUTION]: Programmatically launches and controls Google Chrome through the Chrome DevTools Protocol (CDP), allowing for persistent session management and automated UI interaction while bypassing standard automation detection.
- [REMOTE_CODE_EXECUTION]: Utilizes
Runtime.evaluateto execute JavaScript directly within the browser context and performs local code generation and execution of a Swift script to facilitate rich-text clipboard operations on macOS.
Audit Metadata