logo-creator

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The scripts scripts/remove_bg.py and scripts/vectorize.py attempt to access and read the user's shell configuration file (~/.zshrc) to harvest API keys (REMOVE_BG_API_KEY and RECRAFT_API_KEY) if they are not already set in the environment. Accessing shell profiles is a high-risk behavior as these files typically contain various sensitive environment variables and credentials.
  • [COMMAND_EXECUTION]: The skill performs shell command execution using subprocess.run to call grep for file searching and curl for API communication and file downloads.
  • [DATA_EXFILTRATION]: The skill transmits local image data to external third-party APIs (remove.bg and external.api.recraft.ai) to fulfill its logo processing functions. While this is the stated purpose of the skill, it involves sending user files to external servers.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 03:32 PM
Security Audit — agent-trust-hub — logo-creator