tzai-xhs-cover

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill searches for a local executable named tzai-image in various standard application directories (e.g., ~/.agents/, ~/.claude/, ~/.cursor/) to perform image generation tasks.
  • [EXTERNAL_DOWNLOADS]: If the required engine is missing, the skill provides a command for the user to install the vendor's engine using npx. This targets the official repository of the skill author (kedoupi/tzai-image-skill).
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses shell script blocks to resolve the engine path and generate filenames based on the current date, which is standard behavior for local CLI-based AI skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 02:20 AM
Security Audit — agent-trust-hub — tzai-xhs-cover