content-ops-direct
Pass
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Python scripts (
publish_blog_direct.pyandupload_image_direct.py) located in the agent's skill directory to perform its core functions. These operations are intended and transparently documented. - [EXTERNAL_DOWNLOADS]: The skill interacts with external APIs on
mianhua.meandopenclaw-tu.us.cito upload image files and publish blog content. These network operations are intrinsic to the skill's stated purpose. - [CREDENTIALS_UNSAFE]: The instructions correctly advise users to handle sensitive authentication tokens (
BLOG_UPSERT_TOKENandIMGBED_TOKEN) via environment variables and explicitly forbid hardcoding them into files or responses.
Audit Metadata