qwencloud-image-generation
PassAudited by VirusTotal on Apr 30, 2026.
Findings (1)
The skill bundle provides a legitimate and well-documented interface for image generation and editing via the Qwen/DashScope API. It includes security-conscious instructions for API key management and handles local file uploads to temporary cloud storage as required for image-to-image tasks (scripts/image.py, scripts/qwencloud_lib.py). A self-contained update-check mechanism (scripts/gossamer.py) uses stderr signals to notify the agent of available updates or missing maintenance skills, but the instructions in SKILL.md explicitly require the agent to obtain user consent before performing any installations via 'npx skills'. No evidence of malicious intent, data exfiltration, or unauthorized execution was found.
