baoyu-compress-image

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The script executes local image processing binaries including sips, cwebp, and convert (ImageMagick). These operations are performed using child_process.spawn with argument arrays, which is the recommended secure practice to prevent shell command injection.
  • [DYNAMIC_EXECUTION]: The tool includes logic to dynamically load the sharp library (await import('sharp')) as a fallback image processor. This is a common pattern for optional dependencies and is used here to ensure functionality when system-level binaries are missing.
  • [COMMAND_EXECUTION]: The skill's instructions utilize standard environment tools like npx and bun to execute its local TypeScript scripts, which is consistent with its stated purpose as a developer utility.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 02:09 AM