multimodal-gen

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of the subprocess.run function across multiple files (generate.py, generate_image.py, generate_video.py, prompt_optimizer.py) to execute the system's pass utility and coordinate between local Python scripts.
  • [DATA_EXFILTRATION]: The tool retrieves API credentials from the system's pass password manager (pass api/xingjiabiapi) and transmits them in the Authorization header to the external domain xingjiabiapi.com. While this is functional for the skill's purpose, it involves automated extraction and external transmission of system-stored secrets.
  • [EXTERNAL_DOWNLOADS]: The skill downloads content from external, non-whitelisted domains including xingjiabiapi.com and s3.ffire.cc to save images and videos locally.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input by interpolating it into prompts sent to LLM optimizers and generative models, creating a vulnerability surface for indirect prompt injection.
  • Ingestion points: The user-provided prompt is ingested via sys.argv[1] in generate.py.
  • Boundary markers: None are present to delimit user input from system instructions.
  • Capability inventory: The skill has network access (requests), file system write access (open), and command execution capabilities (subprocess.run).
  • Sanitization: Relies on LLM-based instructions in prompt_optimizer.py to filter or rephrase content rather than deterministic sanitization methods.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 12:36 PM
Security Audit — agent-trust-hub — multimodal-gen