byted-mediakit-image

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a functional extension for image processing (OCR, enhancement, background removal) using the vendor's own CLI tool, mediakit-cli.
  • [SAFE]: The skill references the official npm package @volcengine/mediakit-cli. As this is a resource owned and distributed by the skill's authoring organization (volcengine), it is considered a legitimate dependency.
  • [SAFE]: Security-sensitive operations, such as handling API keys, are instructed to be performed through standard environment variables or a configuration file located at ~/.mediakit/config.json, aligning with industry-standard secret management practices for CLI applications.
  • [SAFE]: No malicious patterns such as prompt injection, obfuscation, or unauthorized data exfiltration were detected across the provided instruction files and references.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 12:44 PM
Security Audit — agent-trust-hub — byted-mediakit-image