telegraph-publisher
Pass
Audited by Gen Agent Trust Hub on Mar 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses POSIX-compliant shell scripts and Python standard libraries to interact with legitimate services including the Telegraph API, GitHub API, and well-known diagram rendering platforms.- [SAFE]: Content processing includes a robust HTML-to-Node conversion mechanism that utilizes a strict whitelist for tags and attributes, ensuring only safe and supported content is published.- [SAFE]: Security best practices are implemented for local file operations, such as using secure umask settings and restricted temporary directory creation to prevent unauthorized access to intermediate files.- [SAFE]: The skill includes explicit privacy warnings and documentation for features involving third-party services, such as diagram rendering, and encourages users to adopt least-privilege principles when configuring GitHub access tokens.- [SAFE]: Sensitive configuration data is managed through local environment files or variables, with no evidence of hardcoded credentials or unauthorized data exfiltration patterns.
Audit Metadata