scientific-schematics

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill's codebase does not contain any malicious patterns, obfuscation, or persistence mechanisms. The primary functionality matches its description and metadata.
  • [COMMAND_EXECUTION]: The scripts/generate_schematic.py script uses subprocess.run with a list of arguments to execute its companion script. By avoiding shell=True and passing arguments as a discrete list, the skill effectively prevents shell injection vulnerabilities.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates communication with the well-known service OpenRouter (openrouter.ai) to generate and review images. This networking is documented, transparent, and uses HTTPS for secure transmission.
  • [SAFE]: Credential management follows best practices by resolving the required OPENROUTER_API_KEY through environment variables or local .env files, ensuring secrets are not hardcoded or exposed in process listings.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — scientific-schematics