.claude/skills/ofox-image-core1 structural issue
- error: description exceeds the 1,024-character Agent Skills limit.
SKILL.md
Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.
Requires OFOX_API_KEY — create one at https://app.ofox.ai. Shared execution layer for the Ofox image API (api.ofox.ai) — validates parameters client-side, sends one synchronous request, base64-decodes the result, saves it to a file, and reports the real usage token counts and the computed dollar cost. Does both text-to-image (generate) and editing an existing image you supply as a local file (edit — change the background, recolour an element, alter a product photo, while leaving the rest of the picture intact). Th…
These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.
These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.
.claude/skills/ofox-image-coreSKILL.mdRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
.agents/skills/ofox-image-coreSKILL.mdRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
skills/ofox-image-coreSKILL.mdRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.
clawhub install @ofoxai/ofox-image-coreclawhub inspect @ofoxai/ofox-image-core --version 1.14.0This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.
$HOME/.ssh/id_rsa$HOME/.ssh/id_rsa$HOME/.ssh/id_rsa$HOME/.ssh/id_rsaThis is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.
The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.
sha256:eebfb06a3e7075d0faf24c99bfe95d322151c06887f60fd6214d83aaba87d98bCHANGELOG.mdreferences/api-params.mdreferences/models-snapshot.jsonreferences/ofox-image.shreferences/pricing.mdreferences/refresh-snapshot.shreferences/test/dryrun.test.shreferences/test/edit.test.shreferences/test/imagecost.test.shreferences/test/keyguard.test.shreferences/test/targetsize.test.shreferences/test/validation.test.shreferences/token-anchors.jsonskill-card.mdSKILL.md**Security and contract strengthening update.** - Now prints an explicit warning (`NOTE:`) with the hostname if `OFOX_API_BASE_URL` is overridden, clarifying where your API key is sent. - Requires `OFOX_API_BASE_URL` to be `https://` (or `http://` for loopback) for added security. - `--extra-form` will not accept values starting with `@` or `<` to avoid unsafe file reads. - Prevents `--extra-json` and `--extra-form` from setting protected request fields (like `model`, `prompt`, `n`, etc.). - Expanded safety documentation and contract for escape hatches and host checks. - Added new tests and improved coverage; some files reorganized.
Both fixed releases were scanned under the current scanner and policy, so finding, permission and dependency changes are available.
Permission escalation detectedThese older immutable releases were observed by prior successful syncs. They remain recorded when a newer release becomes current.
sha256:06545ef1420928d976381bf21eb71526ba09620f9bd2d98a720f23a5af38c2f6sha256:9f3b8892b2adcb1c048fa545f573e48fd4cd279e7d8816ae3ae3ee3fe7d7a356sha256:86a32d21d66c28a0a9a3e411b6555736861645a3e198cc2ec5a7f2ae059816e2