creatok-generate-image

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a mandatory confirmation gate in scripts/run.js, requiring user approval before submitting image generation tasks to the API.
  • [EXTERNAL_DOWNLOADS]: The skill communicates with the vendor's API at www.creatok.ai for image task submission, status polling, and uploading reference images via presigned URLs.
  • [COMMAND_EXECUTION]: The skill uses Node.js fs module to manage local directories and files within the .artifacts folder to store session transcripts and task results.
  • [DATA_EXFILTRATION]: While the skill reads local files to upload as reference images, this behavior is restricted to user-provided paths and targets the vendor's own infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 04:37 PM