vision-analysis

Warn

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes a skill-report.json file containing a self-referential 'security_audit' section. This metadata provides a fake safety verdict and justifications intended to deceive automated auditing tools. This is a form of metadata poisoning.
  • [EXTERNAL_DOWNLOADS]: Setup instructions prompt for the installation of the minimax-coding-plan-mcp package via uvx. This introduces a dependency on external code executed at runtime.
  • [COMMAND_EXECUTION]: The skill directs the agent to provide users with specific shell commands to modify local configuration files such as ~/.config/opencode/opencode.json and run installation scripts.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 7, 2026, 05:52 PM
Security Audit — agent-trust-hub — vision-analysis