soia-pkm-publish-rednote-card

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions focus exclusively on text transformation and content generation. It explicitly disclaims any interaction with external APIs or automatic publishing mechanisms, relying instead on manual user action for the final post. No malicious patterns such as prompt injection, obfuscation, or persistence mechanisms were detected.
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes an installation command using npx that references the vendor's own repository (soia-team/soia-open-skills). This is a standard installation procedure for the vendor's tools and does not involve untrusted third-party sources.
  • [COMMAND_EXECUTION]: No dangerous shell commands, privilege escalation attempts, or unauthorized filesystem operations were detected. The skill is designed to generate text output; any file writing is limited to user-specified paths for saving drafts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 08:22 AM
Security Audit — agent-trust-hub — soia-pkm-publish-rednote-card