image-to-code
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of instructional Markdown content within
SKILL.mdand a metadata summary inskill-report.json. There are no executable scripts, shell commands, or network operations. - [PROMPT_INJECTION]: The instructions use strong language to enforce a specific art-director persona and workflow (e.g., 'MANDATORY', 'CORE DIRECTIVE'), but they do not attempt to bypass AI safety filters, extract system prompts, or override platform-level constraints.
- [DATA_EXFILTRATION]: No sensitive file paths, credential patterns, or network exfiltration techniques are present. The skill focuses on generating and analyzing images within the AI's internal environment.
- [DYNAMIC_CONTEXT_INJECTION]: No use of the dynamic execution syntax (
!command) was found. The skill-report.json metadata mentions 'external_commands' as a risk factor, but manual review confirms these were false positives triggered by rating scale descriptions in the Markdown text (e.g.,(1 = ...)). - [OBFUSCATION]: No encoded strings, hidden characters, or steganographic techniques were detected.
- [METADATA_POISONING]: The
skill-report.jsonfile appears to be an automated audit report generated by a third-party tool. While it makes claims about the skill's safety, it does not contain any malicious instructions or deceptive metadata meant to influence the analyzer.
Audit Metadata