Skip to content
Back to skills

Ai Image Generation Studio

BSecurity

Install and use the official AI Image Generator package, pinned by digest, for paid hosted work on the Beatra service.

  • 6 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 3, 2026
ai-agentspythongobashgitapisecurity

Works with

  • claude code
  • cli
  • api
  • mcp

Security analysis

B88/100
  • criticalDownloads and executes remote scripts — classic supply chain attack

Pro shows the line behind each finding and how to fix it

Scanned October 3, 2026

npx -y skills add ranbot-ai/awesome-skills --skill ai-image-generation-studio --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ai Image Generation Studio?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Ai Image Generation Studio
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/ranbot-ai-ai-image-generation-studio/badge)](https://www.skillsdirectory.com/skills/ranbot-ai-ai-image-generation-studio)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: ai-image-generation-studio
description: Install and use the official AI Image Generator package, pinned by digest, for paid hosted work on the Beatra service. 
category: Document Processing
source: antigravity
tags: [python, markdown, api, mcp, claude, ai, agent, document, image, security]
url: https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/ai-image-generation-studio
---


# AI Image Generator Skill

## Overview

Generate, compose, and edit product images, brand visuals, posters, social graphics, illustrations, and photo variations, from inside Claude Code, Codex, or OpenClaw. The work is produced on the hosted, paid Beatra service
(`mcp.beatra.ai`).

This catalog entry is a **reviewed pointer, not the executable package**. It
contains no client code and performs no Beatra operation by itself. The package
it points to bundles three standard-library Python scripts that make network
calls, store a credential, and can replace their own files. Read
[Install](#install-pinned-verified-approved-twice) and
[Security & Safety Notes](#security--safety-notes) before activating it.

| Pinned identity | Value |
| --- | --- |
| Package | `ai-image-generation-studio` `0.1.4` |
| Archive | `https://cdn.beatra.ai/agent-packages/ai-image-generation-studio/v0.1.4/ai-image-generation-studio-skill-0.1.4.zip` |
| Archive SHA-256 | `b357edb0f9f2546435c89cf1ef8278596e28a7629229a78fcab9804decd13682` |
| Source tree | [`beatra-ai/ai-image-generator-skill@13c7b9b`](https://github.com/beatra-ai/ai-image-generator-skill/tree/13c7b9b2a2197fb91deb6a3a1466124db620c3d1/skills/ai-image-generation-studio) (full SHA `13c7b9b2a2197fb91deb6a3a1466124db620c3d1`) |
| License | MIT No Attribution (MIT-0) |

The archive holds regular files only (no symlinks, no executable bits, no
binaries). Confirm that with the inspect commands below. Every file must be
byte-identical to the source tree at the pinned commit.

## When to Use This Skill

- Use when the user explicitly wants AI Image Generator work produced on Beatra and accepts that it is paid.
- Use when they have agreed to send prompts and any reference images to a third party.
- Do not use for local-only image editing or when no paid render was approved.

## Install (pinned, verified, approved twice)

### Step 1: Download and verify into a review directory

Explain that this downloads an external package from `cdn.beatra.ai`, then ask
for approval. Only after approval:

```bash
umask 077
review_dir="$(mktemp -d)"
cd "$review_dir" || exit 1
curl -fsSLO "https://cdn.beatra.ai/agent-packages/ai-image-generation-studio/v0.1.4/ai-image-generation-studio-skill-0.1.4.zip"
printf '%s  %s\n' \
  'b357edb0f9f2546435c89cf1ef8278596e28a7629229a78fcab9804decd13682' \
  'ai-image-generation-studio-skill-0.1.4.zip' | shasum -a 256 -c -
```

Stop if the check does not print `OK`. The expected digest comes from this
catalog entry, not from a file on the same CDN.

### Step 2: Inspect before activation

```bash
unzip -l ai-image-generation-studio-skill-0.1.4.zip
unzip -q ai-image-generation-studio-skill-0.1.4.zip
find ai-image-generation-studio -type l -print            # expect no output
find ai-image-generation-studio -type f -perm -111 -print # expect no output
grep -n '"auto_update": True' ai-image-generation-studio/scripts/mcp_client.py
```

Optionally confirm byte identity with the public source tree (a second,
independent host):

```bash
git clone --quiet --filter=blob:none --no-checkout https://github.com/beatra-ai/ai-image-generator-skill.git src
git -C src checkout --quiet 13c7b9b2a2197fb91deb6a3a1466124db620c3d1 -- skills/ai-image-generation-studio
(cd ai-image-generation-studio && find . -type f | LC_ALL=C sort | xargs shasum -a 256) > archive.sha
(cd src/skills/ai-image-generation-studio && find . -type f | LC_ALL=C sort | xargs shasum -a 256) > tree.sha
cmp archive.sha tree.sha && echo IDENTICAL
```

Report to the user what the review found: `SKILL.md`, `manifest.json`, the
bundled Markdown references, and `scripts/authorize.py`,
`scripts/mcp_client.py`, `scripts/uninstall.py` (Python 3.10+, standard
library only, no dependency installation, no lifecycle hooks). Summarize the
network, credential, local-state, telemetry, and self-update behavior listed
under [Security & Safety Notes](#security--safety-notes).

### Step 3: Copy in and disable self-update before any other command

Ask for a **second, separate** approval, because this changes agent
configuration. Then copy the reviewed tree to the host's skills directory
(Claude Code shown; use the equivalent path for other hosts) and immediately
turn off silent self-update for that exact path:

```bash
dest="$HOME/.claude/skills/ai-image-generation-studio"
test ! -e "$dest" || { echo "destination exists; stop and ask the user"; exit 1; }
cp -R ai-image-generation-studio "$dest"
python3 "$dest/scripts/mcp_client.py" update --auto off
```

The last command must print
`Automatic Beatra package updates are disabled.` It writes only
`~/.beatra/updates/<id>/state.json` and makes no network request. Run it
before `authorize.py`, `verify`, `tools`, `upload`, or `call`: in this
pinned version self-update is **on by default**. The setting is keyed to the
resolved install path, so repeat it after moving or re-copying the directory.

### Step 4: Authorize as its own decision

Authorization opens a browser sign-in and stores a beare

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…