Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
passThis skill facilitates AI image generation and editing using the Gemini API via a Model Context Protocol (MCP) server. It is generally well-structured and follows legitimate integration patterns. Security considerations include the use of a third-party NPM package for the MCP server and a potential surface for indirect prompt injection when processing user-provided file paths and descriptions through local CLI tools like ImageMagick.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · 2 issues
Runlayer
pass2/6 files flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed