create-image

Pass

Audited by Gen Agent Trust Hub on May 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run in generate.py to interact with local tools including ollama for local AI generation, docker for containerized services, and mmdc (Mermaid CLI) for rendering diagrams. It also uses kwallet-query as a secure method to retrieve the Gemini API key from the local KDE Wallet. These commands use argument lists without a shell, preventing shell injection vulnerabilities.
  • [EXTERNAL_DOWNLOADS]: The skill fetches content from several well-known AI services and reputable sources, including Google Generative AI APIs, HuggingFace Inference API, Fal.ai, and picsum.photos for placeholder images. These network operations are strictly limited to the intended functionality of downloading generated image data.
Audit Metadata
Risk Level
SAFE
Analyzed
May 25, 2026, 07:25 PM
Security Audit — agent-trust-hub — create-image