alterlab-genai-text-to-image

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection vulnerability surface. It is instructed to ingest untrusted data from web search results and existing local project files such as scripts and mood boards. Ingestion points: Workflow steps 1 and 2 in SKILL.md explicitly require reading local files and searching the web. Boundary markers: The skill lacks delimiters or instructions to isolate or ignore potentially malicious commands within the ingested data. Capability inventory: The agent possesses file-read, file-write, and web-search capabilities. Sanitization: There is no mention of sanitizing or validating external content before it is processed or used in further actions.
  • [DATA_EXFILTRATION]: The skill's workflow combines reading local project files with performing web searches. While intended for gathering context, this configuration creates a potential data exfiltration risk where sensitive information from local files could be included in search queries or written to new files if the agent is manipulated by malicious input within those project files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 11:44 PM
Security Audit — agent-trust-hub — alterlab-genai-text-to-image