scientific-schematics
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill's codebase does not contain any malicious patterns, obfuscation, or persistence mechanisms. The primary functionality matches its description and metadata.
- [COMMAND_EXECUTION]: The
scripts/generate_schematic.pyscript usessubprocess.runwith a list of arguments to execute its companion script. By avoidingshell=Trueand passing arguments as a discrete list, the skill effectively prevents shell injection vulnerabilities. - [EXTERNAL_DOWNLOADS]: The skill facilitates communication with the well-known service OpenRouter (
openrouter.ai) to generate and review images. This networking is documented, transparent, and uses HTTPS for secure transmission. - [SAFE]: Credential management follows best practices by resolving the required
OPENROUTER_API_KEYthrough environment variables or local.envfiles, ensuring secrets are not hardcoded or exposed in process listings.
Audit Metadata