telegraph-publisher

Pass

Audited by Gen Agent Trust Hub on Mar 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses POSIX-compliant shell scripts and Python standard libraries to interact with legitimate services including the Telegraph API, GitHub API, and well-known diagram rendering platforms.- [SAFE]: Content processing includes a robust HTML-to-Node conversion mechanism that utilizes a strict whitelist for tags and attributes, ensuring only safe and supported content is published.- [SAFE]: Security best practices are implemented for local file operations, such as using secure umask settings and restricted temporary directory creation to prevent unauthorized access to intermediate files.- [SAFE]: The skill includes explicit privacy warnings and documentation for features involving third-party services, such as diagram rendering, and encourages users to adopt least-privilege principles when configuring GitHub access tokens.- [SAFE]: Sensitive configuration data is managed through local environment files or variables, with no evidence of hardcoded credentials or unauthorized data exfiltration patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 25, 2026, 08:30 AM