tzai-brand

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill employs a shell loop to discover and execute a local script named tzai-image from a set of standard installation directories. This engine is responsible for the actual image generation process.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download a necessary dependency (kedoupi/tzai-image-skill) using the npx package runner. As this resource is provided by the same author (kedoupi), it is treated as a standard vendor-managed resource.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface where user-provided input is passed to a shell command argument (--prompt).
  • Ingestion points: The user-supplied subject variable used in the shell execution snippet in SKILL.md.
  • Boundary markers: None are defined in the provided execution logic to separate command arguments from user content.
  • Capability inventory: The skill can execute local scripts via bash with parameters.
  • Sanitization: No explicit sanitization or escaping mechanisms for the prompt input are documented in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 02:20 AM
Security Audit — agent-trust-hub — tzai-brand