skills/aeonfun/aeon/higgsfield/Gen Agent Trust Hub

higgsfield

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: A static detection for instruction override was identified; however, analysis shows this is a defensive constraint directing the agent to ignore 'ignore previous instructions' commands found in user input, rather than a malicious attempt.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages a known attack surface where untrusted data from user prompts and tool responses is processed.
  • Ingestion points: user-provided prompt variable and Higgsfield API responses from mcp.higgsfield.ai.
  • Boundary markers: explicit text warning that all returned content is untrusted.
  • Capability inventory: tool execution via the Higgsfield MCP server, writes_external_host, and system notifications.
  • Sanitization: specific instructions to discard any agent-directed commands found within processed data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 06:38 PM
Security Audit — agent-trust-hub — higgsfield