xhs-mini-tool

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed to enforce security and compatibility constraints for the Little Red Book mini-tool environment. It explicitly instructs the AI agent to avoid dangerous functions such as eval(), new Function(), and document.write(), and to respect the platform's Content Security Policy (CSP).
  • [EXTERNAL_DOWNLOADS]: The documentation references legitimate and well-known Content Delivery Networks (CDNs) such as unpkg, cdnjs, and jsdelivr for the purpose of importing frontend libraries (Vue, React, Chart.js). These are standard practices for the targeted pure-frontend environment.
  • [SAFE]: The installation instructions provided in the README use standard methods (npx, git clone, curl) to fetch the skill's own configuration files from the author's public repository. No unauthorized or hidden remote code execution patterns were found within the skill's instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 03:19 PM
Security Audit — agent-trust-hub — xhs-mini-tool