lovstudio-document-illustrator

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (scripts/generate_single_image.py and scripts/generate_illustrations.py) using the Bash(python:*) tool to orchestrate the image generation process. This is the primary intended behavior.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes well-known, legitimate Python packages including google-genai, pillow, and python-dotenv from official package registries to facilitate API interaction and image processing.
  • [DATA_EXFILTRATION]: Portions of the user's document content (titles and summaries) are sent to Google's Gemini API to generate contextually relevant imagery. This is an essential component of the skill's functionality and targets a well-known service provider.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 09:43 AM