content-ops-direct

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (publish_blog_direct.py and upload_image_direct.py) located in the agent's skill directory to perform its core functions. These operations are intended and transparently documented.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with external APIs on mianhua.me and openclaw-tu.us.ci to upload image files and publish blog content. These network operations are intrinsic to the skill's stated purpose.
  • [CREDENTIALS_UNSAFE]: The instructions correctly advise users to handle sensitive authentication tokens (BLOG_UPSERT_TOKEN and IMGBED_TOKEN) via environment variables and explicitly forbid hardcoding them into files or responses.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 06:27 PM
Security Audit — agent-trust-hub — content-ops-direct