cesto-creator-toolkit
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The script scripts/start_login.py uses the subprocess module to open the system's default browser to facilitate an authentication flow via magic link. This is a legitimate and standard use case for CLI-based authentication.
- [EXTERNAL_DOWNLOADS]: The scripts/ai_thumbnail_download.py script downloads AI-generated cover images from Cloudinary, which is a well-known and trusted image hosting service. The files are saved to the user's Downloads directory.
- [PERSISTENCE]: The skill maintains session state locally in the ~/.cesto directory. The scripts/_store.py script implements basic XOR encryption for these session tokens and correctly applies restricted file permissions (chmod 0600) to ensure security.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external content such as basket names, descriptions, and risk notes from the Cesto API. To mitigate risks, the SKILL.md instructions explicitly direct the agent to treat all API response content as data rather than instructions and to use specific formatting when rendering this data for the user.
Audit Metadata