po-once-agent-api

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a local script (./scripts/po-once.cjs) to facilitate API interactions. This script performs routine operations such as reading and writing configuration files in standard locations (e.g., ~/.config/po-once/) and reading local media files for upload as directed by the agent.
  • [EXTERNAL_DOWNLOADS]: The helper script communicates with the service's default backend at https://dynamic-lapwing-647.convex.site. Convex is a well-known application platform, and the communication is required for the skill's primary functionality.
  • [DATA_EXFILTRATION]: The skill includes an upload feature that transmits media files to the service provider. This behavior is consistent with the skill's purpose of automating social media posts and is restricted to the specific files requested by the user or agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 04:54 AM