huashu-xhs-image

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local command-line tools and scripts to generate and manage images. Specifically, it calls uv run to execute a local Python script (generate_image.py), uses npx playwright for HTML-to-image conversion, and invokes open to preview generated files.
  • [EXTERNAL_DOWNLOADS]: The skill fetches AI-generated image assets from the official Google Gemini API via the google-genai library.
  • [CREDENTIALS_UNSAFE]: The skill instructions include a command to load the GEMINI_API_KEY from a local environment file located at ~/.claude/.env. This is a standard and acceptable practice for managing secrets in local automation environments.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided content to generate prompts for an AI image model.
  • Ingestion points: User-supplied text summarized in Step 1 of SKILL.md.
  • Boundary markers: The workflow enforces a manual design proposal and user confirmation step (Step 2) before generating the final image, acting as a safeguard against unexpected outputs.
  • Capability inventory: The skill possesses capabilities for network access (Gemini API), local script execution, and file system writes (saving images).
  • Sanitization: The skill does not explicitly perform sanitization on the content summary before interpolating it into the image generation prompt, but the risk is mitigated by the design review phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:55 AM
Security Audit — agent-trust-hub — huashu-xhs-image