aitoearn-earn

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources such as task marketplaces and third-party web pages (via the browser tool). This represents an attack surface for indirect prompt injection. However, the skill implements strong mitigation strategies, including strict instructions to only use data from verified sources, the prohibition of placeholder or synthetic values, and requirements for the validation of media URLs prior to publication.
  • [DYNAMIC_EXECUTION]: The skill contains predefined JavaScript templates intended for execution within a browser context to automate UI interactions and data scraping on the Xiaohongshu platform. These scripts are used for legitimate automation purposes, such as reading comment lists and scrolling search results, and do not demonstrate patterns of injecting untrusted input into executable code.
  • [COMMAND_EXECUTION]: The skill orchestrates multiple specialized tools for environment detection, task lifecycle management, and content distribution across social media platforms. These actions are performed using registered MCP tools within their intended functional scope to facilitate digital affiliate and creator workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 09:24 AM
Security Audit — agent-trust-hub — aitoearn-earn