Atlas / Skills / opensensenova / Sn Image Base

Sn Image BaseBLOCK

skills/opensensenova/sn-image-base

Modular SenseNova skills for building AI-powered office assistants and productivity workflows

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
—
Hosts
1 documented
License
MIT
Stars
5,744
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The skill for the SenseNova-Skills project, providing low-level APIs for image generation, recognition (VLM), and text optimization (LLM).

See SKILL.md for full behavior.

This document describes detailed configurations for the skill.

For installation and usage, please refer to the project's README.md.

Overview

The skill provides the following subcommands:

  • sn-image-generate: image generation
  • sn-image-edit: image editing (SenseNova U1.5 Lite)
  • sn-image-recognize: image recognition (VLM)
  • sn-text-optimize: text optimization (LLM)

The skill supports the following models services:

  • For image generation:
  • SenseNova
  • Nano Banana API
  • OpenAI Image Generation API (e.g. GPT-Image-2)
  • For text and vision chat:
  • SenseNova
  • Models via Anthropic Messages API (e.g. Claude Sonnet 4.6)
  • Models via OpenAI Chat Completion API (e.g. GPT and Gemini/Qwen etc. in OpenAI Compatible API format)

Configurations

Quick Start

We recommend you to try out our SenseNova Token Plan.

Go to to register a free account and get your API key for image generation and chat calls.

Set the following environment variables in ~/.openclaw/.env (or ~/.hermes/.env if you are using Hermes):

# If all capabilities use the same gateway, these two variables are enough.
SN_BASE_URL="https://token.sensenova.cn/v1"
SN_API_KEY=""

# Optional model overrides
SN_IMAGE_GEN_MODEL="sensenova-u1.5-lite"   # or sensenova-u1-fast, or another Token Plan image model
SN_CHAT_MODEL="sensenova-6.8-flash-lite"

Detailed Configurations

With the Quick Start, you can already use this skill.

If you want to confi

Read from source at commit 657860e4d389OBSERVED · 2026-10-07
02

Install

Commands as the repository documents them. They are shown, not run.

pip install -r requirements.txt
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
openclawmentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: sn-image-base
description: |
  Base-layer skill for the SenseNova-Skills project, providing low-level APIs for image generation, recognition (VLM), and text optimization (LLM).
  This skill does not preprocess inputs; it only calls backend services and returns results.
  This skill is not user-facing and is intended for upper-layer skills only.
triggers:
  - "SenseNova-Skills Image Generation"
  - "SenseNova-Skills 图像基础工具"
  - "sn 图像基础工具"
  - "SenseNova 图像基础工具"
  - "SenseNova Image Generation"
  - "sn-image-base"
metadata:
  project: SenseNova-Skills
  tier: 0
  category: infrastructure
  user_visible: false
---

# sn-image-base

## Dependency Installation

```bash
pip install -r requirements.txt
```

## Overview

`sn-image-base` is the base-layer skill (tier 0) of the SenseNova-Skills project and provides four low-level tools:

- `sn-image-generate`: image generation (calls text-to-image-no-enhance API)
- `sn-image-edit`: image editing with SenseNova U1.5 Lite (calls `/images/edits`)
- `sn-image-recognize`: image recognition (uses VLM to analyze image content)
- `sn-text-optimize`: text optimization (uses LLM to process text)

This skill **does not perform any input preprocessing** and only calls backend services to return results.

## Tools List

### sn-image-generate

Image generation tool that calls the text-to-image-no-enhance API.

`--prompt` is required; all other parameters are optional:

| Parameter | Type | Default | Description |
|------|------|--------|------|
| `--prompt` | string | **Required** | Prompt text for image generation |
| `--negative-prompt` | string | `""` | Negative prompt |
| `--image-size` | string | `2k` | Image size preset (case-insensitive). Recommended: `2k`. `4k` is supported by `sensenova-u1.5-lite`; other SenseNova image models may reject it. Other values → `status=failed`. |
| `--aspect-ratio` | string | `16:9` | Aspect ratio, e.g. `1:1`, `16:9`, `9:16` |
| `--seed` | int | `None` | Random seed for reproducible generation |
| `--unet-name` | string | `None` | Specify a UNet model name |
| `--api-key` | string | `SN_IMAGE_GEN_API_KEY` -> `SN_API_KEY` | API key (CLI argument has priority; `MissingApiKeyError` is raised when all are empty) |
| `--base-url` | string | `SN_IMAGE_GEN_BASE_URL` -> `SN_BASE_URL` | API base URL (CLI argument has priority) |
| `--poll-interval` | float | `5.0` | Polling interval (seconds) |
| `--timeout` | float | `300.0` | Timeout (seconds) |
| `--insecure` | flag | `False` | Disable TLS verification |
| `--save-path` | Path | Auto-generated | Save path |

SenseNova image requests explicitly send `watermark=false` by default. Both `sensenova-u1-fast` and `sensenova-u1.5-lite` are supported; U1.5 Lite additionally supports native 4K output. This no-watermark feature is currently in free public beta and may become paid.

### sn-image-edit

Edits one or more reference images with SenseNova U1.5 Lite through the `/images/edits` endpoint. Local paths are converted to Data URLs; HTTP(S) URLs and Data URLs are passed through.

```bash
python scripts/sn_agent_runner.py sn-image-edit \
    --prompt "Change the background to a snowy mountain" \
    --images source.png reference.png \
    --save-path edited.png
```

The edit request uses the official defaults `n=1`, `size=auto`, `watermark=false`, `prompt_extend=true`, and `response_format=url`.

### sn-image-recognize

Image recognition tool that uses VLM (Vision Language Model) to analyze image content. Supports multiple image inputs.

`--images` and `--user-prompt` (or `--user-prompt-path`) are required. All other parameters use three-level defaults (CLI > env var > built-in default):

| Parameter | Type | Built-in Default | Env Var | Description |
|------|------|-----------|---------|------|
| `--api-key` | string | No hardcoded default | `SN_VISION_API_KEY` -> `SN_CHAT_API_KEY` -> `SN_API_KEY` | Chat runtime API key; raises `MissingApiKeyError` when all are unset |
| `--base-url` | string | `SN_CHAT_BASE_URL` default | `SN_VISION_BASE_URL` -> `SN_CHAT_BASE_URL` -> `SN_BASE_URL` | Vision provider base URL; falls back to shared chat/global provider |
| `--model` | string | `sensenova-6.8-flash-lite` | `SN_VISION_MODEL` -> `SN_CHAT_MODEL` | Vision-capable model name |
| `--vlm-type` | string | `openai-completions` | `SN_VISION_TYPE` -> `SN_CHAT_TYPE` | Chat protocol type override |
| `--user-prompt-path` | string | `None` | - | Local file path, mutually exclusive with `--user-prompt` |
| `--system-prompt-path` | string | `None` | - | Local file path, mutually exclusive with `--system-prompt` |

Available values for `--vlm-type`:

- `openai-completions`: OpenAI-compatible `/v1/chat/completions` interface
- `anthropic-messages`: Anthropic Messages `/v1/messages` interface

### sn-text-optimize

Text optimization tool that uses LLM (Language Model) to optimize text content. Does not accept image inputs.

`--user-prompt` (or `--user-prompt-path`) is required. All other parameters use three-level defaults (CLI > env var > built-in default):

| Parameter | Type | Built-in Default | Env Var | Description |
|------|------|-----------|---------|------|
| `--api-key` | string | No hardcoded default | `SN_TEXT_API_KEY` -> `SN_CHAT_API_KEY` -> `SN_API_KEY` | Chat runtime API key; raises `MissingApiKeyError` when all are unset |
| `--base-url` | string | `SN_CHAT_BASE_URL` default | `SN_TEXT_BASE_URL` -> `SN_CHAT_BASE_URL` -> `SN_BASE_URL` | Text provider base URL; falls back to shared chat/global provider |
| `--model` | string | `sensenova-6.8-flash-lite` | `SN_TEXT_MODEL` -> `SN_CHAT_MODEL` | Text model name |
| `--llm-type` | string | `openai-completions` | `SN_TEXT_TYPE` -> `SN_CHAT_TYPE` | Chat protocol type override |
| `--user-prompt-path` | string | `None` | - | Local file path, mutually exclusive with `--user-prompt` |
| `--system-prompt-path` | string | `None` | - | Local file path, mutually exclusive with `--system-prompt` |

Available values for `--llm-type`:

- `openai-compl
05

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (7 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
scripts/sn_agent_runner.py:127
gen_parser.add_argument("--insecure", action="store_true", help="Disable TLS verification")
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
scripts/sn_agent_runner.py:138
edit_parser.add_argument("--insecure", action="store_true", help="Disable TLS verification")
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
scripts/sn_image_base/generation/nano_banana.py:179
image_bytes = base64.b64decode(image)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
scripts/sn_image_base/generation/openai_image.py:319
decoded = base64.b64decode(b64_data)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
scripts/sn_image_base/utils/error_utils.py:228
base64.b64decode(value)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
httpx, pillow, python-dotenv
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 657860e4d389full audit observations/trust-audit/skill/opensensenova__sn-image-base.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-07657860e4d389BLOCKD69first audit
07

Questions

What does the Sn Image Base skill do?

Modular SenseNova skills for building AI-powered office assistants and productivity workflows

Is Sn Image Base safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What can Sn Image Base access on my machine?

The audit observed that it reaches the network. Each of those is consistent with what it says it does. Secrets in the source: none found.

Which assistants does Sn Image Base work with?

Its documentation mentions openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (657860e4d389), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement