baoyu-danger-x-to-markdown
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECREDENTIALS_UNSAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill extracts sensitive session cookies from the user's browser and stores them in a local configuration file.
- Evidence:
scripts/cookies.tsuses the Chrome DevTools Protocol (CDP) to extractauth_tokenandct0cookies from a Chrome instance. - Evidence:
scripts/cookie-file.tswrites these extracted credentials to a local JSON file located at~/Library/Application Support/baoyu-skills/x-to-markdown/cookies.json(or OS equivalent). - [COMMAND_EXECUTION]: The skill executes shell commands to resolve system paths and control browser processes.
- Evidence:
scripts/paths.tsusesexecSyncto runcmd.exe /C "echo %USERPROFILE%"andwslpathfor path resolution in WSL environments. - Evidence:
scripts/cookies.tslaunches a Chrome browser instance via thebaoyu-chrome-cdplibrary to facilitate user login and cookie extraction. - [CREDENTIALS_UNSAFE]: The skill contains a hardcoded bearer token for X API access.
- Evidence:
DEFAULT_BEARER_TOKENinscripts/constants.ts. Note: This appears to be a well-known public bearer token used by the official X web application, rather than a private user secret. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external content from X (tweets and articles) and processes it into markdown, creating a vulnerability surface for indirect prompt injection.
- Ingestion points: X GraphQL API responses processed in
scripts/graphql.tsand formatted inscripts/markdown.ts. - Boundary markers: The skill lacks explicit boundary markers or "ignore embedded instructions" warnings in its markdown output, though it does use standard markdown escaping for media metadata.
- Capability inventory: The skill possesses file system write access (
writeFile), network request capabilities (fetch), and shell execution capabilities (execSync). - Sanitization: Performs basic sanitization on content slugs used for filenames and escapes specific markdown characters in alt-text.
Audit Metadata