baoyu-post-to-x
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local TypeScript files via the
bunruntime for markdown processing and browser automation. It also invokes native system commands (osascripton macOS,powershell.exeon Windows, andxdotool/ydotoolon Linux) specifically to simulate real paste keystrokes, which is a documented method for bypassing synthetic event blocks on sites like X.- [EXTERNAL_DOWNLOADS]: The skill declares dependencies on external packages inpackage.json, includingbaoyu-chrome-cdpandbaoyu-md. These are verified resources belonging to the author 'full-stack-skills' (under the 'baoyu' prefix) and are used for their intended purpose of Chrome DevTools Protocol communication and Markdown parsing.- [DATA_EXPOSURE]: The skill interacts with the local file system to read user-provided markdown, images, and video files for uploading. It creates temporary files in standard OS temp directories (/tmpor OS temp) for HTML conversion and clipboard management. No unauthorized access to sensitive system paths or credential files was found.- [PROMPT_INJECTION]: The instructions contain clear boundaries for the AI agent, specifically regarding execution modes (Computer Use vs. CDP) and safety requirements (requiring explicit user confirmation before clicking 'Publish' or 'Post').
Audit Metadata