skills/hk-hub/agentskills/imagenCN/Gen Agent Trust Hub

imagenCN

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements best practices for secret management, instructing users to store API keys in environment variables rather than hardcoding them. Configuration is managed via standard JSON files in the user home or project directory.
  • [COMMAND_EXECUTION]: The skill utilizes Python scripts to provide a CLI for image generation tasks. This execution is confined to the intended functionality of the tool and does not involve elevated privileges or persistent mechanisms.
  • [EXTERNAL_DOWNLOADS]: The skill connects to official API endpoints for established providers, including Alibaba Cloud (DashScope), ByteDance (Volcano Ark), and Tencent (Hunyuan). It downloads generated images from these services and requires standard Python libraries like dashscope and requests.
  • [PROMPT_INJECTION]: The skill processes external user descriptions to generate images. To prevent unintended behavior, the workflow mandates an interactive 'Refine the prompt' step where the agent must present options and obtain explicit user confirmation before any API calls are executed, providing a human-mediated boundary for untrusted data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:31 PM
Security Audit — agent-trust-hub — imagenCN