skin-creator

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill exclusively utilizes internal platform tools (lobsterai_skin_manage, lobsterai_image_generate) to perform its tasks. It does not attempt to access external URLs, download third-party dependencies, or interact with sensitive system files.
  • [SAFE]: The skill includes a dedicated asset contract in references/asset-contract.md that explicitly prohibits the generation or application of executable code, scripts, fonts, or HTML. This constraint ensures that the output remains limited to harmless raster images.
  • [SAFE]: Defensive instructions are provided to ensure user-provided style descriptions are treated only as creative input. The instructions explicitly state that user input cannot override the tool selection, validation logic, or application rules, mitigating risks of direct or indirect prompt injection.
  • [SAFE]: Data processing is handled safely by enforcing specific formats (e.g., #RRGGBB hex codes) and requiring tool-based verification of palettes and asset registration before application.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 12:43 PM
Security Audit — agent-trust-hub — skin-creator