gpt-image-2-gen

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's installation and operation involve connecting to api.evolink.ai for API key validation and image generation. These requests are directed to the vendor's legitimate infrastructure.
  • [COMMAND_EXECUTION]: The installer uses subprocesses to verify the presence of curl and jq, manage file permissions for its scripts, and check project configurations. These are standard operations for tool installation.
  • [DATA_EXFILTRATION]: User prompts and image URLs are sent to the EvoLink API to facilitate image creation. This is the primary function of the skill and does not involve accessing unauthorized local data.
  • [SAFE]: The installer offers an interactive option to persist the required EVOLINK_API_KEY by adding an export statement to the user's shell profile (.bashrc or .zshrc), which is a common practice for CLI tool configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 01:39 AM