apimodels-image
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Node.js scripts (
generate.mjsandbuild_catalog.mjs) to interact with the apimodels.app API and manage the local model catalog. - [EXTERNAL_DOWNLOADS]: The
generate.mjsscript includes functionality to download generated images from the service's API and save them to a user-defined local path via the--outargument. - [PERSISTENCE]: The skill provides instructions for persisting the API key by adding it to the user's shell profile (
~/.zshrc) or saving it to a dedicated credentials file (~/.apimodels/credentials). The script automatically sets restricted file permissions (0600) on this credentials file to prevent unauthorized access. - [INDIRECT_PROMPT_INJECTION]: The skill acts as a proxy for user-generated prompts and remote image URLs, which are processed by third-party image models.
- Ingestion points: User-provided text prompts and reference image URLs passed as arguments to the
generate.mjsscript (found in SKILL.md). - Boundary markers: The skill relies on the service provider's built-in content moderation filters, which are explicitly referenced in the error handling logic.
- Capability inventory: The skill possesses network access to the
apimodels.appdomain and the ability to write files to the local filesystem. - Sanitization: Implements robust secret management practices, including reading keys from stdin to avoid shell history and masking sensitive values in console output.
Audit Metadata