image-gen

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script uses subprocess.check_output to execute system-level commands (ioreg, wmic) for the purpose of retrieving hardware UUIDs. This is used as a entropy source for hardware-bound key derivation and does not involve user-controlled input.
  • [EXTERNAL_DOWNLOADS]: The skill requires standard Python libraries httpx and cryptography for API communication and encryption. It also downloads generated images from official provider endpoints (OpenRouter, Google, Alibaba, Volcengine) to the local ./output directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 04:00 AM
Security Audit — agent-trust-hub — image-gen