openai-image-gen
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
SKILL.mdfile suggests using theopencommand to view the generatedindex.htmlfile. This is a standard way to open files in the default browser on macOS and is appropriate for the skill's functionality. - [DATA_EXPOSURE]: The skill requires the
OPENAI_API_KEYenvironment variable. It follows best practices by accessing this key through standard environment variables or a command-line argument rather than hardcoding it. - [EXTERNAL_DOWNLOADS]: The script makes POST requests to
api.openai.com(or a user-defined base URL) to generate images. These are legitimate API calls to a well-known service provider for the stated purpose of the skill.
Audit Metadata