baoyu-image-gen

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill communicates with official, well-known AI services (OpenAI, Google, and Alibaba DashScope) using their standard API endpoints.- [SAFE]: Secret management follows industry best practices by loading API keys from local environment files (.env) rather than hardcoding credentials.- [SAFE]: File system operations are restricted to reading configuration and prompt files and writing the generated image output to a user-specified path.- [PROMPT_INJECTION]: While the skill ingests external prompts from files and stdin, creating a surface for indirect prompt injection, the risk is mitigated by the fact that the input is used strictly for image generation rather than agent control logic.* Ingestion points: Prompt content via --prompt, --promptfiles, and stdin in scripts/main.ts.* Boundary markers: None; prompts are passed to APIs as raw strings.* Capability inventory: Network requests to AI providers and file writes for image storage.* Sanitization: No specific text filtering is performed, which is standard for image generation tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 02:10 AM