skills/kuanghs/agent-skills/xfyun-ocr/Gen Agent Trust Hub

xfyun-ocr

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill transmits image data to the iFlytek Spark OCR endpoint at cbm01.cn-huabei-1.xf-yun.com to perform text recognition. This is the primary function of the skill and uses the official API for the service.
  • [CREDENTIALS_UNSAFE]: The script accesses XFYUN_APP_ID, XFYUN_API_KEY, and XFYUN_API_SECRET from environment variables. This is a secure and standard practice for managing API secrets, avoiding hardcoded credentials.
  • [COMMAND_EXECUTION]: The script reads user-specified image files from the local filesystem and encodes them as base64 for processing. No suspicious command execution or shell spawning was detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 10:01 PM
Security Audit — agent-trust-hub — xfyun-ocr