spritecook-workflow-essentials

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill focuses on operational guidelines for an image generation and management service. It explicitly instructs the agent to protect credentials by not asking for API keys or printing authorization headers in the chat.
  • [SAFE]: The skill recommends using official MCP (Model Context Protocol) tools for asset handling and authentication, which is a secure practice for extending AI agent capabilities.
  • [SAFE]: All referenced tools and workflows (e.g., get_credit_balance, generate_game_art, list_recent_assets) are consistent with the stated purpose of game asset creation and management.
  • [SAFE]: The static detector flag regarding concealment appears to be a false positive. The skill's instructions to persist data in a spritecook-assets.json manifest are intended for project organization and workflow continuity, rather than malicious hiding of actions from the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 11:59 AM
Security Audit — agent-trust-hub — spritecook-workflow-essentials