vision-analysis
Warn
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill includes a
skill-report.jsonfile containing a self-referential 'security_audit' section. This metadata provides a fake safety verdict and justifications intended to deceive automated auditing tools. This is a form of metadata poisoning. - [EXTERNAL_DOWNLOADS]: Setup instructions prompt for the installation of the
minimax-coding-plan-mcppackage viauvx. This introduces a dependency on external code executed at runtime. - [COMMAND_EXECUTION]: The skill directs the agent to provide users with specific shell commands to modify local configuration files such as
~/.config/opencode/opencode.jsonand run installation scripts.
Audit Metadata