qwen-image-2

Pass

Audited by Gen Agent Trust Hub on Mar 10, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the infsh CLI tool for image generation, model listing, and authentication. Command access is strictly restricted to the vendor-specific infsh binary via the allowed-tools configuration.
  • [EXTERNAL_DOWNLOADS]: The skill references resources and documentation from the official inference.sh domain and demonstrates the use of npx to manage related vendor-provided skills.
  • [DATA_EXFILTRATION]: All network activity is directed to the vendor's infrastructure (inference.sh) as required for the primary functionality of the skill. No unauthorized access to sensitive local files or data exfiltration to third-party domains was detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 10, 2026, 09:25 PM