visual-identity

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or safety bypasses were identified in the skill instructions or scripts.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with well-known AI service APIs (api.openai.com and api.bfl.ai) to generate and download images. These communications are necessary for the skill's intended functionality.
  • [COMMAND_EXECUTION]: The Python script generate_image.py performs local file operations, such as reading reference images and saving generated outputs to the agent's data directory (~/.letta/). These operations are standard for a file-managing image tool.
  • [DATA_EXFILTRATION]: Local reference images are base64-encoded and sent to external providers (OpenAI or Black Forest Labs) via HTTPS to enable identity-consistent generation. This behavior is documented and required for the skill's reference-based editing workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:46 PM
Security Audit — agent-trust-hub — visual-identity