huashu-xhs-image
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes local command-line tools and scripts to generate and manage images. Specifically, it calls
uv runto execute a local Python script (generate_image.py), usesnpx playwrightfor HTML-to-image conversion, and invokesopento preview generated files. - [EXTERNAL_DOWNLOADS]: The skill fetches AI-generated image assets from the official Google Gemini API via the
google-genailibrary. - [CREDENTIALS_UNSAFE]: The skill instructions include a command to load the
GEMINI_API_KEYfrom a local environment file located at~/.claude/.env. This is a standard and acceptable practice for managing secrets in local automation environments. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided content to generate prompts for an AI image model.
- Ingestion points: User-supplied text summarized in Step 1 of
SKILL.md. - Boundary markers: The workflow enforces a manual design proposal and user confirmation step (Step 2) before generating the final image, acting as a safeguard against unexpected outputs.
- Capability inventory: The skill possesses capabilities for network access (Gemini API), local script execution, and file system writes (saving images).
- Sanitization: The skill does not explicitly perform sanitization on the content summary before interpolating it into the image generation prompt, but the risk is mitigated by the design review phase.
Audit Metadata