visual-identity
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or safety bypasses were identified in the skill instructions or scripts.
- [EXTERNAL_DOWNLOADS]: The skill interacts with well-known AI service APIs (api.openai.com and api.bfl.ai) to generate and download images. These communications are necessary for the skill's intended functionality.
- [COMMAND_EXECUTION]: The Python script
generate_image.pyperforms local file operations, such as reading reference images and saving generated outputs to the agent's data directory (~/.letta/). These operations are standard for a file-managing image tool. - [DATA_EXFILTRATION]: Local reference images are base64-encoded and sent to external providers (OpenAI or Black Forest Labs) via HTTPS to enable identity-consistent generation. This behavior is documented and required for the skill's reference-based editing workflow.
Audit Metadata