generate-image

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a standard wrapper for the OpenRouter Image API. All operations are consistent with its stated purpose of generating and editing images.
  • [EXTERNAL_DOWNLOADS]: The skill communicates with openrouter.ai to fetch model metadata and submit generation requests. It also includes a capability to download images from URLs returned by the API response, which is protected by a requirement for HTTPS and a 64MB size limit to prevent resource exhaustion or insecure downloads.
  • [CREDENTIALS_SAFE]: The script implements a standard hierarchy for resolving the OPENROUTER_API_KEY, searching environment variables and scanning for .env files in a controlled manner. It correctly warns against hardcoding keys.
  • [DATA_EXPOSURE]: The skill reads local image files provided by the user via command-line arguments to use as reference images. This data is Base64 encoded and transmitted over HTTPS to the OpenRouter API, which is the intended core functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — generate-image