higgsfield
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: A static detection for instruction override was identified; however, analysis shows this is a defensive constraint directing the agent to ignore 'ignore previous instructions' commands found in user input, rather than a malicious attempt.
- [INDIRECT_PROMPT_INJECTION]: The skill manages a known attack surface where untrusted data from user prompts and tool responses is processed.
- Ingestion points: user-provided prompt variable and Higgsfield API responses from mcp.higgsfield.ai.
- Boundary markers: explicit text warning that all returned content is untrusted.
- Capability inventory: tool execution via the Higgsfield MCP server, writes_external_host, and system notifications.
- Sanitization: specific instructions to discard any agent-directed commands found within processed data.
Audit Metadata