sprite-atlas

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a standard entry point via run.sh to execute its internal Python CLI. All command-line interactions are restricted to local file manipulation, image processing, and manifest generation as defined in the source code.
  • [EXTERNAL_DOWNLOADS]: Dependencies are limited to established Python libraries (NumPy, OpenCV, Pillow, Typer) managed through pyproject.toml and uv.lock. No remote script fetching or untrusted package sources were detected.
  • [DATA_EXFILTRATION]: The skill lacks network communication capabilities. It operates entirely on local assets (PNG images and JSON profiles) and writes results only to local directories specified by the user or localized job paths.
  • [PROMPT_INJECTION]: The instructions provided in SKILL.md and README.md are technical and deterministic. There are no attempts to override agent behavior, extract system prompts, or bypass safety guardrails.
  • [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or access to sensitive configuration files (e.g., .env, SSH keys, or cloud credentials) were found. The skill uses SHA256 hashing for file integrity checks and receipt generation without exposing sensitive data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — sprite-atlas