qwencloud-usage

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Collection of hardware identifiers for local encryption. The skill executes system-level commands such as wmic, ioreg, sysctl, dmidecode, ifconfig, and ipconfig to gather unique identifiers like CPU ID, Serial Number, and MAC address. These are used locally to derive a machine-specific encryption key for the credential store.
  • [EXTERNAL_DOWNLOADS]: Automated dependency installation. The skill attempts to install the keyring package from the Python Package Index (PyPI) if it is missing and the environment supports a system keychain.
  • [EXTERNAL_DOWNLOADS]: Vendor skill management and updates. The skill provides instructions and logic for the agent to check for updates and install related skills from the QwenCloud/qwencloud-ai repository using the npx skills add command.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 01:26 PM