Atlas / Skills / jeremylongshore / Ideogram Security Basics

Ideogram Security BasicsBLOCK

skills/jeremylongshore/ideogram-security-basics

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
1.11.0
Hosts
1 documented
License
MIT
Stars
2,824
01

Overview

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Read from source at commit 4f83675ca38aOBSERVED · 2026-10-09
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: ideogram-security-basics
description: >-
  Harden an Ideogram integration across credentials, untrusted media, content safety, copyright controls, storage, and tenant authorization. Use when reviewing a threat model or implementing security controls. Trigger with "secure Ideogram", "audit Ideogram image uploads", or "review Ideogram content safety".
allowed-tools: Read,Glob,Grep,Write,Edit
argument-hint: "<application-boundary> <data-class> <environment>"
version: 1.11.0
license: MIT
author: Jeremy Longshore <[email protected]>
tags: [saas, ideogram, security]
model: inherit
effort: high
compatibility: "Designed for Claude Code; security review defaults to repository and fixture evidence"
---
# Ideogram Security Boundary

## Overview

Threat-model the full image lifecycle rather than only the API key. Protect server-side authority, uploaded bytes, prompt and structured-description content, safety decisions, copyright settings, temporary vendor URLs, durable assets, and cross-tenant access.

## Prerequisites

- Data classification, tenant model, rights policy, moderation owner, and retention schedule.
- Architecture showing upload, API, queue, webhook, download, storage, and publishing boundaries.
- Incident paths for credential exposure, unsafe output, malicious media, and unauthorized asset access.

## Current Contract

Ideogram uses a server-side `Api-Key`. Returned items expose `is_image_safe`; unsafe items can have an empty URL. V4 supports `enable_copyright_detection`, and request plus organization settings combine as an OR gate. Generated URLs expire and must not become the application's authorization layer.

## Authentication

Store `IDEOGRAM_API_KEY` in a managed secret store and send it only to `https://api.ideogram.ai`. Authenticate application users separately, authorize each operation and object by tenant, and issue application-owned short-lived download access after durable storage.

## Instructions

1. Map every trust boundary and classify keys, prompts, structured prompts, uploads, masks, generated assets, metadata, and logs.
2. Keep paid API calls behind a server-side policy enforcement point with tenant authentication, authorization, budgets, and rate controls.
3. Validate media signatures, types, dimensions, byte limits, decompression behavior, and malware policy before forwarding.
4. Apply rights, content-safety, and copyright-detection policy before generation and again before publication.
5. Check `is_image_safe`, validate download type and size, store under opaque tenant-scoped keys, and discard vendor URLs.
6. Encrypt retained objects, restrict service identities, log content-free decisions, and enforce deletion.
7. Test key rotation, unsafe output, cross-tenant denial, malicious upload, expired URL, and object deletion.

## Tool Discipline

Use Read, Glob, and Grep to inspect code, policies, infrastructure, and fixtures. Use Write and Edit for approved hardening and tests. Do not open customer media, rotate production keys, weaken policy, or run live generation without authority.

## Approval Boundaries

Require accountable approval for sensitive-image processing, copyright-control changes, external publication, retention exceptions, identity or role changes, key rotation, and production rollout. Fail closed when rights or tenant ownership is ambiguous.

## Error Handling

- Revoke and rotate an exposed key; deleting a log line alone is insufficient.
- Treat unsafe output as a policy result and never auto-rewrite prompts to bypass it.
- Reject redirects, unexpected media types, oversized bodies, and storage keys outside the authorized tenant prefix.

## Output

Return boundaries reviewed, controls present or missing, risk severity, evidence locations, tests, owners, remediation, deployment state, and rollback. Exclude credentials, content, URLs, and exploitable secret locations.

## Examples

- Deny a browser request that attempts to call Ideogram directly with a shared key.
- Persist an approved image to a tenant-owned object key and expose only an application-signed download.

## Validation

Run secret scanning, authorization tests, media parser fixtures, safety branches, storage isolation, deletion, and key-rotation rehearsal. Confirm logs and traces contain no key, prompt, URL, or binary content.

## Resources

- [Current first-party evidence map](references/official-docs.md) — use the dated endpoint, webhook, billing, team, and training links as the contract index for this workflow.
- Recheck the endpoint-specific page and current OpenAPI description before relying on an enum, limit, beta feature, or lifecycle claim.
- Record live observations as environment-specific evidence, not as universal vendor guarantees.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
SKILL.md:33
Store `IDEOGRAM_API_KEY` in a managed secret store and send it only to `https://api.ideogram.ai`. Authenticate application users separately, authorize each operation and object by tenant, and issue ap
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-10-09 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__ideogram-security-basics.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-094f83675ca38aBLOCKD69first audit
06

Questions

What does the Ideogram Security Basics skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Ideogram Security Basics safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What can Ideogram Security Basics access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Ideogram Security Basics work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement