ljg-library

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows secure patterns for its intended functionality, primarily focusing on data processing and image generation.\n- [EXTERNAL_DOWNLOADS]: Fetches book covers, metadata, and author avatars from trusted or well-known services such as Wikipedia, OpenLibrary, and Tencent Weread. These operations are essential to the skill's purpose.\n- [COMMAND_EXECUTION]: Executes local scripts (assets/extract_color.py, assets/gen_illustration.py) and rendering tools (capture.js). These scripts perform specific, non-malicious tasks such as color profile extraction and interfacing with an image generation API.\n- [CREDENTIALS_UNSAFE]: Uses environment variables (WEREAD_API_KEY, LISTENHUB_API_KEY) for authentication with external services. This is a standard and secure practice for secret management in agent environments, avoiding hardcoded credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 06:38 AM
Security Audit — agent-trust-hub — ljg-library