baoyu-image-gen

Pass

Audited by Gen Agent Trust Hub on May 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/providers/google.ts utilizes child_process.execFileSync to invoke the system's curl binary. This is implemented to bypass a known issue where Bun's fetch implementation fails when using HTTP proxies for long-lived connections.\n- [EXTERNAL_DOWNLOADS]: The skill performs legitimate network requests to multiple third-party AI service providers including Google, OpenAI, Azure, Alibaba DashScope, and others to transmit prompt data and retrieve generated images.\n- [SAFE]: The skill follows established patterns for credential management by retrieving API keys from environment variables and specific local configuration files in the .baoyu-skills directory, as described in the documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 25, 2026, 05:38 AM
Security Audit — agent-trust-hub — baoyu-image-gen