steghide
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes workflows for processing external media files (JPEG, BMP, WAV, AU). If these files contain malicious instructions meant to influence the agent's interpretation, they represent a potential injection surface.
- Ingestion points: External files processed via
steghide info,extract, andembed(SKILL.md). - Boundary markers: Not defined in the instructions.
- Capability inventory: The skill documents the use of the
steghidecommand-line utility. - Sanitization: No specific sanitization or validation of the file content is mentioned beyond the tool's native handling.
Audit Metadata