tzai-image

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses curl to interact with the TaoziAPI at https://tzai.kdp.cool, which is the expected behavior for its stated purpose.
  • [DYNAMIC_EXECUTION]: The Bash script uses hardcoded Python templates to handle JSON data and Base64 decoding, ensuring data is processed without executing untrusted code.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: API keys are managed in local configuration files with enforced owner-only permissions (0600), and the doctor command automatically masks keys in output.
  • [INDIRECT_PROMPT_INJECTION]: The skill uses structured visual patterns and explicit text locks to guide the generation process and maintain safety when processing user-provided content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 02:20 AM
Security Audit — agent-trust-hub — tzai-image