generate2dsprite
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided prompts and visual references to generate assets, which is a standard attack surface for indirect prompt injection. However, this is the intended core functionality and the risks are well-mitigated by design.
- Ingestion points: External data enters the context via the
promptandreferenceparameters defined inSKILL.md. - Boundary markers: The skill requires the agent to call
view_imageto inspect local reference files before use, ensuring the data is visible to the system's safety filters. - Capability inventory: The skill's capabilities are restricted to image processing (using
PILandnumpy) and writing assets/metadata to the project directory. It does not perform network operations or execute arbitrary shell commands. - Sanitization: The
generate2dsprite.pyscript includes asanitize_slugfunction that filters filenames to prevent path injection or filesystem issues. - [DYNAMIC_EXECUTION]: The provided Python scripts use
json.loadsfor configuration and do not employ dangerous functions likeeval(),exec(), or unsafe deserialization (e.g.,pickle). All execution is deterministic and based entirely on the local code provided with the skill.
Audit Metadata