image-analysis

Pass

Audited by Gen Agent Trust Hub on Apr 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a bash script (scripts/extract-colors.sh) to automate the installation of Node.js dependencies and the execution of its color analysis logic. This is a standard and safe implementation for local automation tools.\n- [EXTERNAL_DOWNLOADS]: The skill identifies and fetches necessary libraries, specifically 'get-pixels' and 'extract-colors', from the public NPM registry. These are legitimate, well-known packages for handling image data.\n- [REMOTE_CODE_EXECUTION]: The skill performs runtime execution of Node.js code that it downloads via NPM. Because it targets specific, standard packages from a well-known service, this does not pose a security risk in the context of the skill's intended functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 25, 2026, 03:07 PM