baoyu-post-to-weibo
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill uses dynamic code generation for platform-specific operations. In
scripts/copy-to-clipboard.ts, a Swift source string is generated at runtime, written to a temporary file, and executed via theswiftcommand on macOS. Similarly, on Windows, PowerShell scripts are constructed as strings and executed viapowershell.exeto handle image and HTML clipboard data. - [COMMAND_EXECUTION]: The skill uses various system utilities to automate the user interface and manage processes. It invokes
osascripton macOS for keystroke injection (Cmd+V) and application activation. On Linux, it attempts to usexdotoolorydotool, and on Windows, it usesSendKeysvia PowerShell. Additionally,scripts/weibo-utils.tsusesps auxandprocess.killto manage browser instances, and theSKILL.mdfile suggests usingpkillfor troubleshooting. - [EXTERNAL_DOWNLOADS]: The execution instructions recommend using
npx -y bunto run the scripts. This command automatically downloads and executes the Bun runtime from the npm registry if it is not already installed on the host system. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied Markdown files through the
baoyu-mdlibrary to generate HTML for Weibo articles. Ingesting untrusted external data into a workflow that controls a browser via Chrome DevTools Protocol (CDP) creates a surface for indirect injection attacks, although the risk is partially mitigated by the skill's requirement for manual user review before final publication.
Audit Metadata