recraft-image-design
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements strong security practices for managing sensitive data, specifically instructing users to utilize environment variables for API tokens and providing code that prevents credential leakage during HTTP redirects.
- [SAFE]: Incorporates a comprehensive SVG sanitizer using a strict allowlist of tags and attributes, effectively mitigating risks of Cross-Site Scripting (XSS) and unauthorized data exfiltration from potentially malicious API responses.
- [SAFE]: Employs the
defusedxmllibrary to mitigate potential XML-related vulnerabilities, such as Billion Laughs and XML External Entity (XXE) attacks, when processing vector graphics. - [SAFE]: Provides robust input and output validation, including file signature verification, dimension checks, and memory usage limits, which protect the host system from maliciously crafted image files and decompression bombs.
- [SAFE]: Documentation includes clear guidance on privacy, data retention, and rights management, ensuring the agent maintains awareness of the security implications associated with third-party image generation services.
Audit Metadata