apimodels-image

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Node.js scripts (generate.mjs and build_catalog.mjs) to interact with the apimodels.app API and manage the local model catalog.
  • [EXTERNAL_DOWNLOADS]: The generate.mjs script includes functionality to download generated images from the service's API and save them to a user-defined local path via the --out argument.
  • [PERSISTENCE]: The skill provides instructions for persisting the API key by adding it to the user's shell profile (~/.zshrc) or saving it to a dedicated credentials file (~/.apimodels/credentials). The script automatically sets restricted file permissions (0600) on this credentials file to prevent unauthorized access.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a proxy for user-generated prompts and remote image URLs, which are processed by third-party image models.
  • Ingestion points: User-provided text prompts and reference image URLs passed as arguments to the generate.mjs script (found in SKILL.md).
  • Boundary markers: The skill relies on the service provider's built-in content moderation filters, which are explicitly referenced in the error handling logic.
  • Capability inventory: The skill possesses network access to the apimodels.app domain and the ability to write files to the local filesystem.
  • Sanitization: Implements robust secret management practices, including reading keys from stdin to avoid shell history and masking sensitive values in console output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 03:30 AM
Security Audit — agent-trust-hub — apimodels-image