baoyu-post-to-wechat

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes various system utilities using spawn and spawnSync, including ssh for network tunneling, osascript (macOS), powershell.exe (Windows), and xdotool (Linux) for clipboard and keystroke simulation to automate the WeChat Official Account editor. These commands are constructed using fixed templates to prevent shell injection.\n- [EXTERNAL_DOWNLOADS]: The scripts/wechat-image-loader.ts utility is capable of downloading image assets from arbitrary remote HTTP/HTTPS URLs if they are referenced within the input content.\n- [SAFE]: The skill implements its high-capability features, such as SSH tunneling and browser control, with appropriate constraints. No malicious obfuscation, persistence mechanisms, or unauthorized data harvesting patterns were identified. Credentials are sent only to official endpoints like api.weixin.qq.com.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 08:05 AM
Security Audit — agent-trust-hub — baoyu-post-to-wechat