No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by Wh1tZz · Codex Skill · ★ 2
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is xiaoqishuo-card safe to install? View the security audit →
Codex skill: turn one uploaded card cover into an interactive Three.js holographic depth card web app.
| Stars | 2 |
| Forks | 0 |
| Language | TypeScript |
| Category | Codex Skill |
| Quality Score | 40.6126198178118/100 |
| Last Updated | 2026-07-11 |
| Created | 2026-07-11 |
| Platforms | browser, codex, node |
| Est. Tokens | ~13k |
Explore other popular codex skill tools:
xiaoqishuo-card is Codex skill: turn one uploaded card cover into an interactive Three.js holographic depth card web app.. It is categorized as a Codex Skill with 2 GitHub stars.
xiaoqishuo-card is primarily written in TypeScript.
You can find installation instructions and usage details in the xiaoqishuo-card GitHub repository at github.com/Wh1tZz/xiaoqishuo-card. The project has 2 stars and 0 forks, indicating an active community.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: