Yummy Gen Image
Security checks across malware telemetry and agentic risk
Overview
The skill's requirements and instructions are coherent with an image-generation wrapper around the yummycli/Gemini API, but review the npm package provenance and the referenced yummy-shared skill before installing.
This skill appears to do what it says: call yummycli to generate/edit images via Gemini using your GEMINI_API_KEY. Before installing: (1) verify the npm package @yummysource/yummycli is from a trusted publisher and inspect its README/repo if possible; (2) check the related yummy-shared skill for any additional environment variables or behaviors; (3) confirm the GEMINI_API_KEY you provide has limited scope and can be rotated/revoked; (4) be aware that running the CLI will upload any referenced local images to the provider—do not pass sensitive images. If you are uncomfortable, install yummycli yourself and run it manually rather than granting the skill automatic install rights.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
64/64 vendors flagged this skill as clean.
