logo-designer-generator

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides documentation and examples for a legitimate image generation API. No malicious code, credential harvesting, or unauthorized persistence mechanisms were detected.
  • [COMMAND_EXECUTION]: The skill includes usage examples for curl and npx onekey to interact with the service's API endpoints. These commands are standard for developer integrations and are used appropriately within the context of the skill.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted user data. 1. Ingestion points: User-controlled prompt and brief_inputs fields in the image_generator API request. 2. Boundary markers: Absent; there are no instructions to the agent to isolate these inputs from its core reasoning logic. 3. Capability inventory: The skill facilitates network requests to agent.deepnlp.org. 4. Sanitization: No input validation or escaping mechanisms are specified for the user-provided content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 01:55 PM
Security Audit — agent-trust-hub — logo-designer-generator