skills/anbeime/skill/baoyu-post-to-x/Gen Agent Trust Hub

baoyu-post-to-x

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: Orchestrates system interactions via spawn and spawnSync to manage clipboard data and simulate keystrokes using platform-specific tools like osascript (macOS), powershell.exe (Windows), and xdotool (Linux).
  • [EXTERNAL_DOWNLOADS]: The scripts/md-to-html.ts utility includes functionality to fetch remote images from external URLs during the Markdown conversion process.
  • [COMMAND_EXECUTION]: Programmatically launches and controls Google Chrome through the Chrome DevTools Protocol (CDP), allowing for persistent session management and automated UI interaction while bypassing standard automation detection.
  • [REMOTE_CODE_EXECUTION]: Utilizes Runtime.evaluate to execute JavaScript directly within the browser context and performs local code generation and execution of a Swift script to facilitate rich-text clipboard operations on macOS.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 01:20 AM
Security Audit — agent-trust-hub — baoyu-post-to-x