multimodal-gen
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill makes network requests to an external API endpoint (
xingjiabiapi.com) to initiate image and video generation. - [EXTERNAL_DOWNLOADS]: It automatically downloads media files from arbitrary URLs provided in the API responses, including those from
s3.ffire.ccand other potentially untrusted domains. - [COMMAND_EXECUTION]: The skill uses
subprocess.runto execute internal Python components and the system'spassutility to retrieve API keys. - [DATA_EXFILTRATION]: User-provided prompts are sent to a third-party domain for both content generation and prompt optimization, potentially exposing sensitive input to an external service.
Audit Metadata