sprite-atlas
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a standard entry point via
run.shto execute its internal Python CLI. All command-line interactions are restricted to local file manipulation, image processing, and manifest generation as defined in the source code. - [EXTERNAL_DOWNLOADS]: Dependencies are limited to established Python libraries (NumPy, OpenCV, Pillow, Typer) managed through
pyproject.tomlanduv.lock. No remote script fetching or untrusted package sources were detected. - [DATA_EXFILTRATION]: The skill lacks network communication capabilities. It operates entirely on local assets (PNG images and JSON profiles) and writes results only to local directories specified by the user or localized job paths.
- [PROMPT_INJECTION]: The instructions provided in
SKILL.mdandREADME.mdare technical and deterministic. There are no attempts to override agent behavior, extract system prompts, or bypass safety guardrails. - [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or access to sensitive configuration files (e.g.,
.env, SSH keys, or cloud credentials) were found. The skill uses SHA256 hashing for file integrity checks and receipt generation without exposing sensitive data.
Audit Metadata