chatgpt-image-ad

Pass

Audited by Gen Agent Trust Hub on May 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script uses the macOS sips utility within scripts/generate_image.py to verify the pixel dimensions of downloaded images. The command is executed using a safe argument list that prevents shell injection.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with the Arcads API at https://external-api.arcads.ai to upload reference images and download generated creatives. This is the primary intended function of the skill.
  • [CREDENTIALS_UNSAFE]: The skill instructs the user to store API keys in a .env file and uses standard Python logic to load them, adhering to best practices for secret management.
Audit Metadata
Risk Level
SAFE
Analyzed
May 27, 2026, 12:12 AM
Security Audit — agent-trust-hub — chatgpt-image-ad