skills/xingyu4j/skills/xingyu/Gen Agent Trust Hub

xingyu

Warn

Audited by Gen Agent Trust Hub on Mar 4, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill configures GitHub Actions workflows in references/setting-up.md that depend on external, reusable workflows from the sxzz/workflows repository. These workflows are executed during CI/CD operations and represent a remote dependency from a source outside of the trusted organizations list.
  • [COMMAND_EXECUTION]: In references/monorepo.md, the skill includes an alias.ts script that uses the Node.js fs module to dynamically read, parse, and overwrite the tsconfig.alias.json configuration file based on calculated project paths.
  • [COMMAND_EXECUTION]: The skill defines and encourages the use of various automation commands (e.g., @antfu/ni suite, pnpm run lint --fix, npx simple-git-hooks) which execute shell scripts and interact with package managers in the local development environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 4, 2026, 01:48 AM