visual-asset-design

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill provides explicit instructions to systematically bypass automated image moderation systems (e.g., DashScope's 'green-net'). It teaches the agent to use euphemisms and 'occupational cues' instead of direct terms that might trigger filters (such as police or military identifiers) and advises on modifying 'prompt fingerprints' to ensure successful generation after a rejection.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection because it incorporates external data into its output prompts.
  • Ingestion points: Processes data from 'grounding context', 'reference images', and 'user descriptions' to build visual asset prompts.
  • Boundary markers: No delimiters or instructions to ignore embedded commands within the ingested data are mentioned.
  • Capability inventory: The generated output is used to drive downstream image and video generation processes.
  • Sanitization: There is no evidence of validation or sanitization of the input data before interpolation into the prompt templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 12:39 PM
Security Audit — agent-trust-hub — visual-asset-design