tzai-image
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
curlto interact with the TaoziAPI athttps://tzai.kdp.cool, which is the expected behavior for its stated purpose. - [DYNAMIC_EXECUTION]: The Bash script uses hardcoded Python templates to handle JSON data and Base64 decoding, ensuring data is processed without executing untrusted code.
- [DATA_EXPOSURE_AND_EXFILTRATION]: API keys are managed in local configuration files with enforced owner-only permissions (0600), and the
doctorcommand automatically masks keys in output. - [INDIRECT_PROMPT_INJECTION]: The skill uses structured visual patterns and explicit text locks to guide the generation process and maintain safety when processing user-provided content.
Audit Metadata