Ideogram Core Workflow BSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-09Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: ideogram-core-workflow-b description: >- Choose among Ideogram edit, remix, describe, magic-prompt, upscale, background, reframe, and transformation tools. Use when modifying or analyzing an image under explicit rights and safety controls. Trigger with "edit with Ideogram", "describe an image for Ideogram", or "choose an Ideogram image tool". allowed-tools: Read,Glob,Grep,Write,Edit argument-hint: "<desired-change> <input-rights> <output-destination>" version: 1.11.0 license: MIT author: Jeremy Longshore <[email protected]> tags: [saas, ideogram, image-editing] model: inherit effort: high compatibility: "Designed for Claude Code; live image operations require approved rights, network access, and credit" --- # Ideogram Image Transformation Routing ## Overview Map a requested image change to the narrowest current Ideogram operation. Keep edit, remix, structured description, prompt assistance, and outcome-focused tools distinct so rights, uploaded bytes, model control, and output review remain visible. ## Prerequisites - Proven rights to process the input and an approved purpose, destination, and retention period. - Input validation for supported image type, size, dimensions, and any required mask. - A server-side key, positive credit, content policy, and durable asset store. ## Current Contract Current surfaces include V4 edit with prompt, V4 remix, V4 describe into a structured JSON prompt, V4 magic prompt, V3 edit/remix, and tools for background removal or replacement, object or logo removal, reframe, ad resize, colorways, material swap, upscale, and text layerization. Outcome-focused tools may choose the model; use model endpoints when direct model control is required. ## Authentication Send `IDEOGRAM_API_KEY` as `Api-Key` only from a trusted server to `https://api.ideogram.ai`. Do not log the key, source image, mask, prompt, structured description, output URL, or generated bytes. ## Instructions 1. Verify input ownership, consent, data class, permitted transformation, destination, and deletion deadline. 2. Choose describe for a reusable V4 structured prompt, edit for localized prompt-guided change, remix for variation, or a named tool for its specific outcome. 3. Validate uploaded type and byte limit before the API boundary; V4 describe accepts JPEG, PNG, or WebP up to 25 MB. 4. Build only the selected endpoint's multipart fields and set bounded deadlines, outputs, and concurrency. 5. Validate transport, schema, `is_image_safe`, and expected tool outcome before publishing or chaining work. 6. Download approved output immediately, store it under an opaque key, and delete temporary input and URL metadata. 7. Record rights, route, safety, storage, and cleanup receipts without copying content. ## Tool Discipline Use Read, Glob, and Grep to inspect upload validation, route selection, storage, and fixtures. Use Write and Edit only for approved code or documentation. Do not upload, transform, publish, or retain an image merely because the skill was invoked. ## Approval Boundaries Require accountable approval for biometric, confidential, licensed, customer, or regulated imagery; logo removal; external publication; copyright-detection policy changes; model changes; or durable retention. Decline ambiguous rights rather than attempting a transform. ## Error Handling - Reject unsupported media, oversized uploads, missing masks, and incompatible fields before spending credit. - A structured describe result uses normalized `[0,1000]` boxes ordered `[y_min,x_min,y_max,x_max]`; preserve that coordinate contract. - Do not retry unsafe results by automatically weakening or rewriting the policy-sensitive request. ## Output Return selected operation, rights decision, input validation summary, status, safe-output count, opaque identifiers, storage and retention state, review decision, and rollback receipt. Exclude source or output content, prompts, credentials, and URLs. ## Examples - Describe an approved product photo, review the structured prompt, then generate a controlled campaign variant. - Select background removal for an isolated catalog subject; select V4 edit when the requested change depends on a prompt and mask. ## Validation Test route selection and every rejected input class, compare fields with endpoint docs, verify safety and coordinate handling, and confirm temporary media deletion. A visually plausible output does not prove rights, retention, or route correctness. ## Resources - [Current first-party evidence map](references/official-docs.md) — use the dated endpoint, webhook, billing, team, and training links as the contract index for this workflow. - Recheck the endpoint-specific page and current OpenAPI description before relying on an enum, limit, beta feature, or lifecycle claim. - Record live observations as environment-specific evidence, not as universal vendor guarantees.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__ideogram-core-workflow-b.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Ideogram Core Workflow B skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Ideogram Core Workflow B safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Ideogram Core Workflow B access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Ideogram Core Workflow B work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.