huashu-image-upload
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a local Python script (
/Users/alchain/Documents/写作/tools/upload_image.py) to perform image uploads to the ImgBB service. This tool is part of the vendor's local environment and is used to convert temporary AI-generated URLs into permanent web links.- [INDIRECT_PROMPT_INJECTION]: The skill analyzes user-supplied article content to identify thematic image needs. This involves processing untrusted external data within the agent's context to generate prompts for image creation and placement. The skill provides no specific boundary markers for this data ingestion.
Audit Metadata