tzai-diagram

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill employs a shell-based discovery mechanism to locate a local engine script named tzai-image across multiple platform-specific directories (e.g., .agents, .claude, .cursor).
  • [COMMAND_EXECUTION]: It executes the discovered engine using bash, interpolating user-provided diagram types and subjects directly into the command arguments.
  • [EXTERNAL_DOWNLOADS]: In the event the required engine is missing, the skill provides a specific command for the user to install the tzai-image-skill package from the author's repository using npx.
  • [COMMAND_EXECUTION]: The skill generates dynamic filenames for output images using the shell's date command and user-supplied diagram category names.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 02:20 AM
Security Audit — agent-trust-hub — tzai-diagram