together-images

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill is authored by the official vendor 'togethercomputer' and interacts exclusively with Together AI's verified infrastructure (api.together.xyz and docs.together.ai).
  • [EXTERNAL_DOWNLOADS]: Includes legitimate references to well-known machine learning and image hosting services (Hugging Face, Replicate, CivitAI, Pixabay, Pexels) for the purpose of fetching LoRA adapters and example images. These operations are core to the skill's utility and involve reputable sources.
  • [COMMAND_EXECUTION]: Provides standard scripts using the Together Python and Node.js SDKs. The scripts handle image generation, local saving, and basic editing through documented API parameters.
  • [CREDENTIALS_SAFE]: API security is handled correctly by referencing the TOGETHER_API_KEY environment variable rather than hardcoding secrets. Instructions explicitly guide users on securing their own environments.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests external data (image URLs and text prompts), this is the primary intended function of an image generation tool. The implementation uses standard SDK methods and does not execute the ingested content in an unsafe context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:27 AM
Security Audit — agent-trust-hub — together-images