hatch-pet
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes several bundled Python scripts in the
scripts/directory to handle spritesheet assembly and validation. Scripts such asfinalize_pet_run.pyandrender_animation_videos.pyuse thesubprocessmodule to execute internal processing tasks and theffmpegutility. These executions are performed using structured argument lists rather than shell strings and include validations to prevent command injection and path traversal. - [EXTERNAL_DOWNLOADS]: The
scripts/generate_pet_images.pycomponent performs network requests to the OpenAI API for image generation and editing. These operations target well-known OpenAI endpoints and are necessary for the skill's primary functionality. The skill also incorporates instructions for the agent to fetch configuration from local system paths designated for skill integration. - [DATA_EXFILTRATION]: The skill transmits pet concepts and visual prompts to external generation services. To prevent unauthorized data access, the skill implements rigorous path traversal checks (verified by the
test_generate_pet_images.pyregression test) to ensure that only files within the intended project directory or official generation directories are processed and uploaded. Sensitive API keys are managed through standard environment variables.
Audit Metadata