baoyu-post-to-x

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local TypeScript files via the bun runtime for markdown processing and browser automation. It also invokes native system commands (osascript on macOS, powershell.exe on Windows, and xdotool/ydotool on Linux) specifically to simulate real paste keystrokes, which is a documented method for bypassing synthetic event blocks on sites like X.- [EXTERNAL_DOWNLOADS]: The skill declares dependencies on external packages in package.json, including baoyu-chrome-cdp and baoyu-md. These are verified resources belonging to the author 'full-stack-skills' (under the 'baoyu' prefix) and are used for their intended purpose of Chrome DevTools Protocol communication and Markdown parsing.- [DATA_EXPOSURE]: The skill interacts with the local file system to read user-provided markdown, images, and video files for uploading. It creates temporary files in standard OS temp directories (/tmp or OS temp) for HTML conversion and clipboard management. No unauthorized access to sensitive system paths or credential files was found.- [PROMPT_INJECTION]: The instructions contain clear boundaries for the AI agent, specifically regarding execution modes (Computer Use vs. CDP) and safety requirements (requiring explicit user confirmation before clicking 'Publish' or 'Post').
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 08:05 AM
Security Audit — agent-trust-hub — baoyu-post-to-x