baoyu-post-to-x
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses various system commands to interact with the environment, including
osascript(macOS),powershell.exe(Windows), andxdotool/ydotool(Linux) to simulate keystrokes and manage the clipboard. - Evidence:
scripts/paste-from-clipboard.tsexecutesosascriptto sendCmd+Vkeystrokes to target applications.scripts/x-utils.tsusesexecSyncto runcmd.exefor WSL environment detection. - [DYNAMIC_EXECUTION]: The skill generates and runs temporary Swift code to interface with native macOS clipboard APIs for rich media support.
- Evidence:
scripts/copy-to-clipboard.tscreates and runs a temporary.swiftfile containingAppKitcode to handle image and HTML data. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided Markdown content, which presents a surface for indirect prompt injection if the content contains malicious instructions intended for the agent or downstream consumers.
- Ingestion points: Markdown files ingested by
scripts/x-article.tsandscripts/md-to-html.ts. - Boundary markers: None present in the prompt interpolation logic.
- Capability inventory: Includes file system access, network interaction via CDP, and system command execution.
- Sanitization: Employs basic HTML entity escaping for special characters in
scripts/md-to-html.ts. - [EXTERNAL_DOWNLOADS]: The skill fetches remote image assets defined in Markdown files for local processing and upload.
- Evidence:
scripts/md-to-html.tsutilizes theresolveImagePathfunction to download remote URLs to a temporary directory.
Audit Metadata