Watercolor Art Generator
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill is internally consistent: it implements a simple CLI wrapper that calls the Neta/TalesOfAI image API and only needs an API token; no unrelated credentials, installs, or suspicious behaviors are present.
This skill appears to be what it claims: a small CLI wrapper that calls the Neta/TalesOfAI image API and returns an image URL. Before installing: (1) note the package source is listed as unknown and there is no homepage — verify the publisher or review the code yourself (the included JS is small and readable). (2) Avoid passing long-lived secrets on the command line on multi-user machines (process listings can expose them); prefer using ephemeral tokens or running in an isolated environment. (3) If you install and use it, consider using an API token you can rotate/revoke and run the script in a sandbox or container if you have concerns about provenance.
SkillSpector
SkillSpector findings are pending for this release.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
