youmind-web-clipper

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the youmind CLI to perform operations like listing boards and creating links. It includes a validation step that requires URLs to start with 'http://' or 'https://' before being processed, which serves as a security control against command injection.\n- [EXTERNAL_DOWNLOADS]: To function, the skill guides the user or agent to install the @youmind-ai/cli package from the NPM registry. This is a recognized external dependency provided by the vendor (YouMind-OpenLab) and is standard for CLI-based agent skills.\n- [CREDENTIALS_UNSAFE]: The skill uses a YOUMIND_API_KEY for authentication. The setup instructions explicitly forbid the agent from asking users to paste their keys directly into the chat, recommending secure environment configuration instead to avoid exposing secrets in chat history.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 03:39 AM