baoyu-xhs-images

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute specific shell commands (using bun or npx) to interface with the codex CLI or local wrapper scripts for image generation when native tools are unavailable. This is a functional requirement for the skill's operation and includes guidance on discovering the wrapper path locally.
  • [SAFE]: Implements a mandatory "Smart Confirm" (Step 2) and "First-Time Setup" (Step 0) policy, ensuring the user is in control of configuration and generation actions. This prevents the agent from performing actions without explicit user consent.
  • [SAFE]: The skill uses a structured prompt assembly process (described in references/workflows/prompt-assembly.md) that translates user content into image generation prompts without exposing the agent to command injection or safety bypasses during the translation phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 08:18 AM
Security Audit — agent-trust-hub — baoyu-xhs-images