hatch-pet

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes several bundled Python scripts in the scripts/ directory to handle spritesheet assembly and validation. Scripts such as finalize_pet_run.py and render_animation_videos.py use the subprocess module to execute internal processing tasks and the ffmpeg utility. These executions are performed using structured argument lists rather than shell strings and include validations to prevent command injection and path traversal.
  • [EXTERNAL_DOWNLOADS]: The scripts/generate_pet_images.py component performs network requests to the OpenAI API for image generation and editing. These operations target well-known OpenAI endpoints and are necessary for the skill's primary functionality. The skill also incorporates instructions for the agent to fetch configuration from local system paths designated for skill integration.
  • [DATA_EXFILTRATION]: The skill transmits pet concepts and visual prompts to external generation services. To prevent unauthorized data access, the skill implements rigorous path traversal checks (verified by the test_generate_pet_images.py regression test) to ensure that only files within the intended project directory or official generation directories are processed and uploaded. Sensitive API keys are managed through standard environment variables.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — hatch-pet