aitoearn-earn
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources such as task marketplaces and third-party web pages (via the
browsertool). This represents an attack surface for indirect prompt injection. However, the skill implements strong mitigation strategies, including strict instructions to only use data from verified sources, the prohibition of placeholder or synthetic values, and requirements for the validation of media URLs prior to publication. - [DYNAMIC_EXECUTION]: The skill contains predefined JavaScript templates intended for execution within a browser context to automate UI interactions and data scraping on the Xiaohongshu platform. These scripts are used for legitimate automation purposes, such as reading comment lists and scrolling search results, and do not demonstrate patterns of injecting untrusted input into executable code.
- [COMMAND_EXECUTION]: The skill orchestrates multiple specialized tools for environment detection, task lifecycle management, and content distribution across social media platforms. These actions are performed using registered MCP tools within their intended functional scope to facilitate digital affiliate and creator workflows.
Audit Metadata