xhs-login

Pass

Audited by Gen Agent Trust Hub on Mar 24, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains logic to save a Base64-encoded QR code to a temporary file (/tmp/xhs-qrcode.png) and open it using system utilities (open on macOS, xdg-open on Linux). This is a functional fallback mechanism for users whose clients cannot render images directly and does not pose a security threat in this context.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 24, 2026, 07:59 AM