ljg-library
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows secure patterns for its intended functionality, primarily focusing on data processing and image generation.\n- [EXTERNAL_DOWNLOADS]: Fetches book covers, metadata, and author avatars from trusted or well-known services such as Wikipedia, OpenLibrary, and Tencent Weread. These operations are essential to the skill's purpose.\n- [COMMAND_EXECUTION]: Executes local scripts (
assets/extract_color.py,assets/gen_illustration.py) and rendering tools (capture.js). These scripts perform specific, non-malicious tasks such as color profile extraction and interfacing with an image generation API.\n- [CREDENTIALS_UNSAFE]: Uses environment variables (WEREAD_API_KEY,LISTENHUB_API_KEY) for authentication with external services. This is a standard and secure practice for secret management in agent environments, avoiding hardcoded credentials.
Audit Metadata