Is jau123/creative-toolkit safe?
Yes. jau123/creative-toolkit is safe to install. Oathe's behavioral security audit gave the creative-toolkit skill by jau123 a trust score of 91/100 with 2 findings, none critical or high.
https://github.com/openclaw/skills/tree/main/skills/jau123/creative-toolkit
Is jau123/creative-toolkit safe to install?
This is a legitimate AI image generation MCP server skill that provides a unified interface for multiple image generation providers. The main security consideration is that it executes external NPM packages, but this is transparent and documented with source code references.
What security issues were found in jau123/creative-toolkit?
Category Scores
Findings (2)
MEDIUM Remote NPM Package Execution -25 ▶
The skill instructs users to run 'npx meigen@latest' which downloads and executes external Node.js code from npmjs.com. While the skill is transparent about this behavior and provides source code links, this still represents a code execution risk as external code will be downloaded and run on the user's system.
LOW API Credential Handling -20 ▶
The skill requires users to configure API tokens (MEIGEN_API_TOKEN) which will be accessible to the MCP server process. This is standard for MCP servers but represents a potential exposure risk if the server process is compromised.
Should I install jau123/creative-toolkit?
Oathe's verdict for jau123/creative-toolkit is SAFE with a trust score of 91/100. Recommendation: Install with caution.