baoyu-post-to-x

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses various system commands to interact with the environment, including osascript (macOS), powershell.exe (Windows), and xdotool/ydotool (Linux) to simulate keystrokes and manage the clipboard.
  • Evidence: scripts/paste-from-clipboard.ts executes osascript to send Cmd+V keystrokes to target applications. scripts/x-utils.ts uses execSync to run cmd.exe for WSL environment detection.
  • [DYNAMIC_EXECUTION]: The skill generates and runs temporary Swift code to interface with native macOS clipboard APIs for rich media support.
  • Evidence: scripts/copy-to-clipboard.ts creates and runs a temporary .swift file containing AppKit code to handle image and HTML data.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided Markdown content, which presents a surface for indirect prompt injection if the content contains malicious instructions intended for the agent or downstream consumers.
  • Ingestion points: Markdown files ingested by scripts/x-article.ts and scripts/md-to-html.ts.
  • Boundary markers: None present in the prompt interpolation logic.
  • Capability inventory: Includes file system access, network interaction via CDP, and system command execution.
  • Sanitization: Employs basic HTML entity escaping for special characters in scripts/md-to-html.ts.
  • [EXTERNAL_DOWNLOADS]: The skill fetches remote image assets defined in Markdown files for local processing and upload.
  • Evidence: scripts/md-to-html.ts utilizes the resolveImagePath function to download remote URLs to a temporary directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:07 AM
Security Audit — agent-trust-hub — baoyu-post-to-x