baoyu-post-to-weibo

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill uses dynamic code generation for platform-specific operations. In scripts/copy-to-clipboard.ts, a Swift source string is generated at runtime, written to a temporary file, and executed via the swift command on macOS. Similarly, on Windows, PowerShell scripts are constructed as strings and executed via powershell.exe to handle image and HTML clipboard data.
  • [COMMAND_EXECUTION]: The skill uses various system utilities to automate the user interface and manage processes. It invokes osascript on macOS for keystroke injection (Cmd+V) and application activation. On Linux, it attempts to use xdotool or ydotool, and on Windows, it uses SendKeys via PowerShell. Additionally, scripts/weibo-utils.ts uses ps aux and process.kill to manage browser instances, and the SKILL.md file suggests using pkill for troubleshooting.
  • [EXTERNAL_DOWNLOADS]: The execution instructions recommend using npx -y bun to run the scripts. This command automatically downloads and executes the Bun runtime from the npm registry if it is not already installed on the host system.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied Markdown files through the baoyu-md library to generate HTML for Weibo articles. Ingesting untrusted external data into a workflow that controls a browser via Chrome DevTools Protocol (CDP) creates a surface for indirect injection attacks, although the risk is partially mitigated by the skill's requirement for manual user review before final publication.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 03:32 AM
Security Audit — agent-trust-hub — baoyu-post-to-weibo