generate-image
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a standard wrapper for the OpenRouter Image API. All operations are consistent with its stated purpose of generating and editing images.
- [EXTERNAL_DOWNLOADS]: The skill communicates with
openrouter.aito fetch model metadata and submit generation requests. It also includes a capability to download images from URLs returned by the API response, which is protected by a requirement for HTTPS and a 64MB size limit to prevent resource exhaustion or insecure downloads. - [CREDENTIALS_SAFE]: The script implements a standard hierarchy for resolving the
OPENROUTER_API_KEY, searching environment variables and scanning for.envfiles in a controlled manner. It correctly warns against hardcoding keys. - [DATA_EXPOSURE]: The skill reads local image files provided by the user via command-line arguments to use as reference images. This data is Base64 encoded and transmitted over HTTPS to the OpenRouter API, which is the intended core functionality.
Audit Metadata