skills/xixu-me/skills/xdrop/Gen Agent Trust Hub

xdrop

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill downloads and processes file manifests from external Xdrop servers. An attacker-controlled server could serve malicious metadata intended to influence the agent's logic.\n
  • Ingestion points: The scripts/download.mjs script fetches transfer descriptors and manifest files from remote URLs.\n
  • Boundary markers: The skill does not use explicit delimiters when reporting file paths or transfer statuses back to the agent.\n
  • Capability inventory: The scripts are capable of writing to the local filesystem and performing network requests.\n
  • Sanitization: A sanitizePath function is implemented in scripts/download.mjs to filter path traversal sequences like '..' and strip illegal OS-specific characters.\n- [EXTERNAL_DOWNLOADS]: The tool performs network communication with user-provided Xdrop server URLs to transfer binary data and encrypted manifests.\n- [COMMAND_EXECUTION]: The skill requires the agent to execute bundled JavaScript scripts using the Bun runtime to perform its file and network tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 11:30 PM
Security Audit — agent-trust-hub — xdrop