baoyu-article-illustrator
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses established runtimes like
bunandnpxto execute local scripts and wrappers for image generation. This behavior is documented and integrated into the workflow for backend resolution. - [EXTERNAL_DOWNLOADS]: The skill mentions using
npxwhich may download thebunruntime if missing. This is a standard developer tool interaction and falls under trusted service rules. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided article content to extract core arguments and generate image prompts. While this presents an indirect injection surface, the risk is mitigated by the skill's structured approach to analyzing content before prompt construction.
- [DATA_EXFILTRATION]: No unauthorized network operations or credential harvesting were found. Network access for image generation is routed through designated tools and services such as Codex and official image generation backends.
Audit Metadata