Scan Report
This report was generated in Chinese. Some content may be in Chinese.
5 /100
x-bookmark-triage
X/Twitter书签自动分类工具,调用Claude评分后发布到Discord
合法的X书签整理工具,将Twitter书签通过Claude分类并发布到Discord,代码透明,无恶意行为。
Safe to install
该技能安全可信,可正常使用。建议确保.env文件不提交到版本控制。
| Resource | Declared | Inferred | Status | Evidence |
|---|---|---|---|---|
| Filesystem | WRITE | WRITE | ✓ Aligned | SKILL.md:11-12 声明数据文件写入 |
| Network | READ | READ | ✓ Aligned | SKILL.md:13 仅调用X/Discord/Anthropic官方API |
| Shell | WRITE | WRITE | ✓ Aligned | SKILL.md:11 spawnSync+curl用于API调用 |
| Environment | READ | READ | ✓ Aligned | 读取OAuth凭证和API密钥,功能必需 |
17 findings
Medium External URL 外部 URL
https://developer.x.com README.md:28 Medium External URL 外部 URL
https://discord.com/developers/applications README.md:32 Medium External URL 外部 URL
https://console.anthropic.com README.md:35 Medium External URL 外部 URL
https://x.com/someone/status/123 README.md:59 Medium External URL 外部 URL
https://x.com/... README.md:81 Medium External URL 外部 URL
https://x.com/anthropic/status/... README.md:128 Medium External URL 外部 URL
https://x.com/@username/status/1234567890 SKILL.md:55 Medium External URL 外部 URL
http://www.apple.com/DTDs/PropertyList-1.0.dtd references/cron-setup.md:31 Medium External URL 外部 URL
https://x.com/i/oauth2/authorize?... references/oauth-setup.md:34 Medium External URL 外部 URL
https://api.x.com/2/users/me references/oauth-setup.md:73 Medium External URL 外部 URL
https://api.x.com/2/oauth2/token scripts/backlog-sweep.js:71 Medium External URL 外部 URL
https://api.x.com/2/users/$ scripts/backlog-sweep.js:112 Medium External URL 外部 URL
https://discord.com/api/v10/channels/$ scripts/poll-channel.js:47 Medium External URL 外部 URL
https://nodejs.org scripts/setup-check.js:27 Medium External URL 外部 URL
https://api.fxtwitter.com/$ scripts/triage-url.js:70 Medium External URL 外部 URL
https://markdown.new/$ scripts/triage-url.js:90 Medium External URL 外部 URL
https://twitter.com/i/oauth2/authorize scripts/x-oauth2-authorize.js:45 File Tree
13 files · 73.6 KB · 2103 lines JavaScript 6f · 1308L
Markdown 5f · 751L
Shell 1f · 23L
Text 1f · 21L
├─
▾
references
│ ├─
adapting.md
Markdown
│ ├─
cron-setup.md
Markdown
│ └─
oauth-setup.md
Markdown
├─
▾
scripts
│ ├─
backlog-sweep.js
JavaScript
│ ├─
bookmark-poll.js
JavaScript
│ ├─
poll-channel.js
JavaScript
│ ├─
run-poll.sh
Shell
│ ├─
setup-check.js
JavaScript
│ ├─
triage-url.js
JavaScript
│ └─
x-oauth2-authorize.js
JavaScript
├─
LICENSE.txt
Text
├─
README.md
Markdown
└─
SKILL.md
Markdown
Security Positives
✓ OAuth 2.0 PKCE流程实现正确
✓ Token文件使用0o600权限保护
✓ Token值从不打印到stdout
✓ 所有网络调用仅指向合法官方API(api.x.com, discord.com, api.anthropic.com)
✓ 代码无混淆、无base64执行、无eval滥用
✓ 使用spawnSync显式参数避免shell注入
✓ 文档与行为完全一致