Sharing pages and documents securely can require several tools and manual steps. This skill publishes content and manages ShareOne links from one workflow.
The canonical policy requires operator review before any installation action.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Agent request
Review the Skillstore skill "shareone" from https://skillstore.io/skills/sudoprivacy-shareone.md and its manifest at https://skillstore.io/api/skills/sudoprivacy-shareone/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.
Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
The audit confirmed remote pipe-to-shell execution, unsafe filename insertion into HTML, transcript exposure of guest keys, and authenticated requests to caller-selected origins. Most scanner matches are false positives from documentation, JavaScript template literals, loopback tests, and expected CLI file or network operations. No prompt injection or obfuscated payload evidence was found. Static review was capped at 400/531 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This outputs or requires relaying a newly issued API key through the agent transcript, exposing a bearer credential to logs and conversation retention.
This outputs or requires relaying a newly issued API key through the agent transcript, exposing a bearer credential to logs and conversation retention.
This outputs or requires relaying a newly issued API key through the agent transcript, exposing a bearer credential to logs and conversation retention.
This outputs or requires relaying a newly issued API key through the agent transcript, exposing a bearer credential to logs and conversation retention.
This outputs or requires relaying a newly issued API key through the agent transcript, exposing a bearer credential to logs and conversation retention.
- `GUEST_KEY_CREATED:<api_key>`:**阻塞性用户通知**。分隔线之后是需要原样转发给用户的完整通知文本(含临时 API Key、绑定账号链接和保存提醒)。必须先把该通知发
This outputs or requires relaying a newly issued API key through the agent transcript, exposing a bearer credential to logs and conversation retention.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
This accepts or propagates a caller-controlled API origin that later receives authenticated ShareOne requests, enabling credential disclosure to an untrusted host.
import mermaid from 'https://cdn.jsdelivr.net/npm/mermaid@11/dist/mermaid.esm.min.mjs';
The generated page imports a floating major-version script from a CDN without integrity verification, exposing published pages to dependency compromise.
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.