gzh-ai-feed

Pass

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The script communicates with the official RedFoxHub API at https://redfox.hk to retrieve curated article metadata and statistics.
  • [COMMAND_EXECUTION]: Uses subprocess.run to manage local automation tasks, including setting up macOS LaunchAgents or crontab entries for the subscription feature, and invoking the system browser to open generated reports.
  • [CREDENTIALS_UNSAFE]: The skill requires a REDFOX_API_KEY, which it correctly handles by reading from environment variables or a local configuration file, avoiding hardcoded secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 12, 2026, 07:50 PM
Security Audit — agent-trust-hub — gzh-ai-feed