Product PhotoshootSAFE
Supports GPT Image 2, Seedance & ComfyUI, with a 1,400+ prompt library, carefully crafted hooks and a multi-task orchestration system
Overview
Supports GPT Image 2, Seedance & ComfyUI, with a 1,400+ prompt library, carefully crafted hooks and a multi-task orchestration system
3541031621f7OBSERVED · 2026-10-09What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: Product Photoshoot Workflow description: >- Optional product imagery planning. Use when the user asks for help to "shoot a product", "make e-commerce product images", "product photography set", "电商产品图", "产品多角度图", "brand product visuals", or provides a single product photo and asks for marketing-ready variations. Can suggest distinct directions (lifestyle scene, macro detail, scale/context, marketing layout) from one reference image. NOT for: portraits, generic illustration, logo design, video creation — use other skills or generate_image directly. version: 0.1.0 --- # Product Photoshoot Workflow Turn one product reference photo into a brand-ready set matching the requested count, each emphasizing a different sales angle. ## Optional assistant scope Use this planning workflow only when the caller asks for creative development. A supplied storyboard, prompt set or approved count/budget can call tools directly. Preserve explicit tool/model/provider, prompt, ratio, references and quality choices. Do not impose a new concept-selection or approval step on resolved inputs. Discovery is available to any workflow; delegation is optional. Return handles/results to the caller, which owns previews, downloads and presentation. Visual descriptions require actual inspection. ## Choosing a dedicated Skill When choosing a tool for an unresolved request, prefer the dedicated workflow: for transparent cutouts use `remove_background`; for ecommerce detail images use `generate_product_detail_images`; for posters use `generate_marketing_poster`; for white, smart or custom product backgrounds use `generate_ai_background`; for still-image upscaling use `upscale_image`. Call these tools directly. Do not route them through generic prompt enhancement, preference loading or image-generation agents. Preserve an upstream workflow's explicit tool selection. They require MeiGen credentials and purchased credits; ComfyUI and OpenAI-compatible providers cannot run them. No daily free credits or Web free attempts apply. Use `list_skills` for current inputs, defaults and prices. Ask only for missing required information or unresolved output scope. An explicit requested count/modules/quality already authorizes that scope; do not reconfirm it or add paid images. Product Detail MCP requires explicit `modules` (use `[]` for custom modules only); each selected module is one image. Posters need only a subject; images and copy are optional. Use defaults for unspecified settings and never invent product facts, dates or discounts. Use real accessible images only. Both remote and local connections expose `upload_skill_image`; local npm also accepts real file paths for the four ordinary image-input workflows. If the host cannot read an attachment, ask for a public direct HTTPS image URL; never invent paths or base64. **Upscale is a separate original-image path:** pass the original public direct HTTPS PNG/JPEG/WebP URL as `imageUrl`, at most 64 MiB and 64 MP. Local npm also accepts an actual original PNG/JPEG/WebP path in `imageUrl` through its dedicated upload route, preserving source dimensions. For readable attachment bytes, call `upload_skill_image` with `purpose: "upscale"` (base64 up to 3 MiB decoded); use the returned `imageUrl`. Do not use `purpose: "reference"` or generic reference compression for Upscale. If the host cannot read the attachment, request a real public original-image URL. On every MCP submission, including the first, pass `confirmedCredits` from the live `list_skills` quote within the user or upstream workflow accepted budget; reuse an already explicit acceptance. This pre-dispatch recheck is not an atomic spending cap. Use `mode: "crisp"` (default) or `"creative"` as offered by `list_skills`. `allowDownscale` is opt-in: explain that it permits preprocessing to at most 4096px/16 MP and the final output can be smaller than the original; set it only after the user explicitly accepts that tradeoff. Upscale accepts still images, not video. For `upscale_resize_required` or `price_changed`, return the resize/cost decision to the caller. Reuse an already explicit acceptance; otherwise obtain acceptance of the new tradeoff or price before submitting a new `requestId` with accepted `allowDownscale` and `confirmedCredits`. These are changed, confirmed inputs—not a blind retry of an interrupted submission. The caller generates and persists `requestId` for each logical step. For interrupted submissions, call `check_skill` with the original skill/ID before retrying. Follow `nextAction`, including waiting `afterSeconds`; retry only when instructed, using its exact original ID and parameters. Never use a new ID as a blind retry or automatically pay for failed-module replacements. Auth/payment/input rejections require their indicated action instead of polling. Return structured status, task handles and completed image URLs to the caller, with failed modules and refund states separately. The caller owns display and downloads; end users do not need to manage technical IDs. ## When to trigger - User uploads a product photo and says "make e-commerce images", "design a campaign", "I need product shots" - User says 电商产品图 / 产品多角度图 / 产品拍摄 / 产品营销图 - Anyone asking for "a set of product images" with a reference attached ## Prerequisites 1. **A reference image is required** — the user MUST provide a product photo (URL or local path). If they have not, ask once: "Please share the product photo you want me to work from." Do NOT try to invent a product without a reference. 2. For the generic photoshoot below, confirm a provider is configured (MeiGen / OpenAI-compatible / ComfyUI). Dedicated Skills require MeiGen. If not, hand off to `/meigen:setup`. ## The 4 directions These four directions are optional starting points. Match the requested count and existing plan. Ask which directions to use only if that choice is unresolved; do not reconfirm an approved set. | # | Direction | Aspect | Intent | |---|-
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
3541031621f7full audit observations/trust-audit/skill/jau123__product-photoshoot.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 3541031621f7 | SAFE | B | 89 | first audit |
Questions
What does the Product Photoshoot skill do?
Supports GPT Image 2, Seedance & ComfyUI, with a 1,400+ prompt library, carefully crafted hooks and a multi-task orchestration system
Is Product Photoshoot safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Product Photoshoot access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
What do I need installed to use Product Photoshoot?
Its own instructions reference modules. Dependencies are pinned to exact versions.
How current is this page?
The grade is for one exact copy of the source (3541031621f7), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.