skills/whytryharder/skills/flux-image/Gen Agent Trust Hub

flux-image

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill leverages the allowed-tools metadata to restrict shell access exclusively to the belt command. This scopes the agent's capabilities to only the intended CLI tool, reducing the attack surface for arbitrary command execution.
  • [EXTERNAL_DOWNLOADS]: The skill recommends the installation of the belt-sh/cli package and references configuration files from the inference-sh GitHub repository. These are legitimate dependencies for the platform integration described in the skill's purpose.
  • [SAFE]: No patterns of prompt injection, data exfiltration, or obfuscation were identified. The use of external image URLs for image-to-image tasks is a standard feature of the underlying model and does not pose an inherent security risk in this context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 05:02 AM
Security Audit — agent-trust-hub — flux-image