Install
$ agentstack add skill-tiga001-captain-who-image-generation ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Image Generation
Use image_generation for image creation and editing. Keep every call in the typed envelope { "request": { ... }, "reason": "..." }.
Workflow
- Choose
generatewhen the result is based only on text. Sendrequest.operation="generate"and a completerequest.prompt. Setrequest.sizePresetonly when the user requests a supported output size. - Choose
editwhen an existing image must influence the result. Sendrequest.operation="edit", a completerequest.prompt, and exactly one authorizedrequest.inputPath. - Copy the exact image path returned by the producing tool or supplied by the user into
request.inputPath. This includes workspace paths, authorized absolute/system paths, attachmentreadPathvalues, generatedimage-artifact://...paths, and revision-boundskill://...paths. For an attachment, callattachments_listfirst and copy its exactreadPath. Never build a source object, guess an attachment path, or substitute a display name, ID, or private saved path. - Write
reasonas a short, non-empty, user-readable sentence describing the purpose of that specific generation call. It is display and audit metadata only and never grants access. - Inspect the returned status and Artifact contract. Report success only when status is
succeededand the returned Artifact is verified. - On success, the model result returns one top-level
path, normally an application-ownedimage-artifact://...reference. Copy that same path intoread_image.pathto inspect it, or into a laterimage_generationedit request'sinputPathto edit it again. Do not build asourceobject, combine URI and filesystem fields, search attachments, or generate the image again merely to inspect it. - The Artifact
pathis a stableread_imagereference, not a filesystem destination. If the user asks to place the image in the workspace or another user-visible folder, use the separately returned exactsavedPathwith the ordinary authorized file/command path. Never derivesavedPathfrom the Artifact URI, and do not claim the image was exported until that separate operation succeeds. - A model with image-input capability may also receive the generated pixels transiently during the generation execution.
visualInputDeliveryuses stable values such asattachedDuringGeneration; it does not mean pixels remain attached in later model requests. In a later turn, callread_imagewith the exact returnedpathbefore claiming to have visually re-inspected the image.
Never send a URL, API key, model ID, provider ID, executable, raw base64, or data URL. Provider selection, credentials, model configuration, input encoding, execution identity, and Artifact storage are host responsibilities. Do not replace this tool with curl, a custom network request, or an ad-hoc script.
If the tool is unavailable or reports a configuration error, preserve that result and tell the user to review the image-generation Skill switch in Settings → Skills and the API/model configuration in Settings → Configuration → Image Generation; do not attempt a network fallback. Preserve failed, cancelled, and indeterminate outcomes exactly. Always inspect failure.retryable before considering another call. When it is false, do not retry it automatically; report the failure and follow the returned recovery guidance. When it is true, retry at most once and only when that still matches the user's intent. Never loop retries. An indeterminate result may represent a request that reached the provider and must never be retried automatically.
Product watermark
Treat a platform-added watermark such as “AI生成” as a product configuration result, not an image quality defect. Do not change that configuration or make the watermark invisible by cropping, covering, repainting, editing, or regenerating. If the user does not want it, direct them to turn off “添加水印” in “设置 → 配置 → 图片生成”, save, and generate again. This rule concerns the product's generated-image watermark, not third-party copyright watermarks or marks of unknown origin.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Tiga001
- Source: Tiga001/Captain_Who
- License: Apache-2.0
- Homepage: https://captainwhoagent.com
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.