baoyu-image-gen
Pass
Audited by Gen Agent Trust Hub on May 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/providers/google.tsutilizeschild_process.execFileSyncto invoke the system'scurlbinary. This is implemented to bypass a known issue where Bun'sfetchimplementation fails when using HTTP proxies for long-lived connections.\n- [EXTERNAL_DOWNLOADS]: The skill performs legitimate network requests to multiple third-party AI service providers including Google, OpenAI, Azure, Alibaba DashScope, and others to transmit prompt data and retrieve generated images.\n- [SAFE]: The skill follows established patterns for credential management by retrieving API keys from environment variables and specific local configuration files in the.baoyu-skillsdirectory, as described in the documentation.
Audit Metadata