baoyu-danger-x-to-markdown

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECREDENTIALS_UNSAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill extracts sensitive session cookies from the user's browser and stores them in a local configuration file.
  • Evidence: scripts/cookies.ts uses the Chrome DevTools Protocol (CDP) to extract auth_token and ct0 cookies from a Chrome instance.
  • Evidence: scripts/cookie-file.ts writes these extracted credentials to a local JSON file located at ~/Library/Application Support/baoyu-skills/x-to-markdown/cookies.json (or OS equivalent).
  • [COMMAND_EXECUTION]: The skill executes shell commands to resolve system paths and control browser processes.
  • Evidence: scripts/paths.ts uses execSync to run cmd.exe /C "echo %USERPROFILE%" and wslpath for path resolution in WSL environments.
  • Evidence: scripts/cookies.ts launches a Chrome browser instance via the baoyu-chrome-cdp library to facilitate user login and cookie extraction.
  • [CREDENTIALS_UNSAFE]: The skill contains a hardcoded bearer token for X API access.
  • Evidence: DEFAULT_BEARER_TOKEN in scripts/constants.ts. Note: This appears to be a well-known public bearer token used by the official X web application, rather than a private user secret.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external content from X (tweets and articles) and processes it into markdown, creating a vulnerability surface for indirect prompt injection.
  • Ingestion points: X GraphQL API responses processed in scripts/graphql.ts and formatted in scripts/markdown.ts.
  • Boundary markers: The skill lacks explicit boundary markers or "ignore embedded instructions" warnings in its markdown output, though it does use standard markdown escaping for media metadata.
  • Capability inventory: The skill possesses file system write access (writeFile), network request capabilities (fetch), and shell execution capabilities (execSync).
  • Sanitization: Performs basic sanitization on content slugs used for filenames and escapes specific markdown characters in alt-text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:32 AM
Security Audit — agent-trust-hub — baoyu-danger-x-to-markdown