soia-media-cover-image

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the use of an external CLI tool to perform its primary function. It instructs the agent to invoke the codex exec command with arguments derived from the generation context, including prompt file paths and target aspect ratios.\n- [EXTERNAL_DOWNLOADS]: The installation instructions reference the author's repository on GitHub, and the skill requires the presence of the codex CLI tool on the system path to function. These are documented as standard operational dependencies.\n- [DATA_EXFILTRATION]: The skill interacts with the local filesystem to manage the image generation lifecycle. It reads model metadata from ~/.codex/models_cache.json and moves generated assets from temporary cache locations (~/.codex/generated_images/) to the final output directory. It also manages configuration and prompt history in ~/.config/soia-skills/ and specified article directories. These actions are restricted to relevant tool data and do not involve sensitive credential files or unauthorized network transmission.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 01:56 PM
Security Audit — agent-trust-hub — soia-media-cover-image