imagegenskill
Warn
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill includes instructions in
references/codex-network.mddesigned to bypass system-level security controls. It specifically advises users to setapproval_policy = "never"and enablenetwork_accessin the configuration, effectively disabling safety prompts and sandbox restrictions. - [PROMPT_INJECTION]: The file
imagegenskill_audit_result_v1.jsonis a deceptive document masquerading as a pre-verified security audit result. It falsely claims the skill is "Production Ready" and has passed security gates, which is a self-referential attempt to influence security reviewers and automated scanners. - [EXTERNAL_DOWNLOADS]: The documentation in
references/cli.mdreferences the use of external Python packagesopenaiandpillowfor image generation, which contradicts the primary claim inSKILL.mdthat the skill avoids image models and external dependencies.
Audit Metadata