跳到主要内容
知仓学习社ZHICANG

image-generation

Generate or edit images from text prompts. Use when the user asks to create, draw, design, or edit an image, illustration, photo, icon, poster, or a…

读凭据联网读文件严重 0 · 高危 18zhayujie/CowAgent

它会碰到什么

扫了多少2 个文本文件,54 KB
它会碰到什么读凭据联网读文件
命中总数42 处
命中统计严重 0 · 高 18 · 中 18 · 低 6
逐条看命中(18 条严重或高危)
  • scripts/generate.py:225cred-envread
    value = (os.environ.get(env_name) or "").strip()
  • scripts/generate.py:1106cred-envread
    config = json.loads(os.environ.get(_CUSTOM_PROVIDER_ENV, ""))
  • scripts/generate.py:1151cred-envread
    "OpenAI": os.environ.get("OPENAI_API_KEY", ""),
  • scripts/generate.py:1152cred-envread
    "Gemini": os.environ.get("GEMINI_API_KEY", ""),
  • scripts/generate.py:1153cred-envread
    "Seedream": os.environ.get("ARK_API_KEY", ""),
  • scripts/generate.py:1154cred-envread
    "Qwen": os.environ.get("DASHSCOPE_API_KEY", ""),
  • scripts/generate.py:1155cred-envread
    "MiniMax": os.environ.get("MINIMAX_API_KEY", ""),
  • scripts/generate.py:1156cred-envread
    "LinkAI": os.environ.get("LINKAI_API_KEY", ""),
  • scripts/generate.py:1159cred-envread
    "OpenAI": os.environ.get("OPENAI_API_BASE", "https://api.openai.com/v1"),
  • scripts/generate.py:1160cred-envread
    "Gemini": os.environ.get("GEMINI_API_BASE", "https://generativelanguage.googleapis.com"),
  • scripts/generate.py:1161cred-envread
    "Seedream": os.environ.get("ARK_API_BASE", "https://ark.cn-beijing.volces.com/api/v3"),
  • scripts/generate.py:1162cred-envread
    "Qwen": os.environ.get("DASHSCOPE_API_BASE", "https://dashscope.aliyuncs.com"),
  • scripts/generate.py:1163cred-envread
    "MiniMax": os.environ.get("MINIMAX_API_BASE", "https://api.minimaxi.com"),
  • scripts/generate.py:1164cred-envread
    "LinkAI": os.environ.get("LINKAI_API_BASE", "https://api.link-ai.tech"),
  • scripts/generate.py:1234cred-envread
    model = args.get("model") or os.environ.get("SKILL_IMAGE_GENERATION_MODEL") or ""
  • scripts/generate.py:1237cred-envread
    provider_id = args.get("provider") or os.environ.get("SKILL_IMAGE_GENERATION_PROVIDER") or ""
  • scripts/generate.py:1246cred-envread
    output_base = os.environ.get("IMAGE_OUTPUT_DIR")
  • scripts/generate.py:1248cred-envread
    workspace = os.environ.get("AGENT_WORKSPACE") or os.getcwd()

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Image Generation

Generate and edit images using AI models. The script automatically picks a backend based on which API keys are configured — you don't need to specify a model unless the user explicitly names one. Never guess or invent a model: when the user doesn't name one, omit model entirely so the configured default/provider is used.

Supported models (passed via model only when the user asks for a specific one):

  • OpenAIgpt-image-2.5-flare (recommended default: best quality/latency trade-off), gpt-image-2.5-sunburst (highest editing precision), gpt-image-2, gpt-image-1
  • Gemini Nano Banananano-banana-2, nano-banana-pro, nano-banana
  • Seedream (Volcengine Ark)seedream-5.0-lite, seedream-4.5
  • Qwen (DashScope)qwen-image-2.0, qwen-image-2.0-pro
  • MiniMaximage-01

Usage

Run scripts/generate.py with a JSON argument. Use the absolute <base_dir> path — do NOT cd into the skill directory, since it is a builtin skill and gets reset on restart (anything written there is lost).

python <base_dir>/scripts/generate.py '<json_args>'

Images are saved to the workspace (or the open project dir) under images/, so they persist and stay reachable to the client.

Set bash timeout to at least 600 seconds, as image generation can take 30–200s per provider, and the script may try multiple providers sequentially. Call it synchronously (do not run it in the background) and wait for its output in the same turn.

Parameters

| Parameter | Type | Required | Default | Description |

|-----------|------|----------|---------|-------------|

| prompt | string | yes | — | Image description |

| image_url | string / list | no | null | Input image(s) for editing: local file path or URL. Multi-image fusion is supported (pass a list) |

| quality | string | no | auto | low / medium / high (only some backends honour this) |

| size | string | no | auto | 512 / 1K / 2K / 3K / 4K, or pixel value (1024x1024) |

| aspect_ratio | string | no | null | 1:1 / 3:2 / 2:3 / 16:9 / 9:16 / 21:9 (some backends also support extreme ratios like 1:4 / 8:1) |

Higher quality and larger size cost more and run slower. In normal cases, when the user does not explicitly specify, low or medium is sufficient. Only use high when the user asks for it.

Example — generate

python <base_dir>/scripts/generate.py '{"prompt": "A corgi astronaut floating in space"}'

With aspect ratio:

python <base_dir>/scripts/generate.py '{"prompt": "Isometric miniature city of Shanghai at sunset", "size": "2K", "aspect_ratio": "16:9"}'

Important: Editing vs Generating

When the user asks to edit, modify, or improve an existing image, pass the original image via image_url. Prefer local file paths directly — the script handles file reading internally. Without image_url, the script generates a brand-new image instead of editing.

Example — edit (image-to-image)

python <base_dir>/scripts/generate.py '{"prompt": "Add a Santa hat to the dog", "image_url": "/path/to/dog.png"}'

Multi-image fusion — pass a list:

python <base_dir>/scripts/generate.py '{"prompt": "Combine these characters into a group photo", "image_url": ["/path/a.png", "/path/b.png"]}'

Output

Prints JSON to stdout:

{
  "model": "doubao-seedream-5-0-260128",
  "images": [
    {"url": "/path/to/output.png"}
  ]
}

After success, display the image to the user. You can either embed it in markdown (![description](/path/to/output.png)) or use the send tool.

On error:

{
  "error": "error message"
}

Setup

The script needs at least one of these API keys (set via env_config or config.json):

OPENAI_API_KEY / GEMINI_API_KEY / ARK_API_KEY / DASHSCOPE_API_KEY / MINIMAX_API_KEY / LINKAI_API_KEY

Each also has an optional *_API_BASE for custom endpoints. The script automatically picks the first configured backend and falls back to the next if it fails — no need to specify a model.

Error Handling

If the script returns an error after trying all configured backends, do NOT retry with the same parameters — the failure is almost always a configuration issue (wrong API key, unsupported API base). Tell the user to fix it via env_config, then retry.

Notes

  • HTTP timeout is 300s — high-resolution generation can take over 200s.
  • Omit quality / size to let the model pick automatically (auto).
  • Input images for editing are auto-compressed to ≤ 4MB / longest edge ≤ 4096px.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 47,000
本站分层T1
该仓技能数3
原文件路径skills/image-generation/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 3 个技能