muapi-image-edit
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data that could potentially contain malicious instructions targeting the image editing models.
- Ingestion points:
edit-image.shandenhance-image.shaccept untrusted data via the--image-urland--promptarguments. - Boundary markers: The skill does not use specific delimiters or instructions to ensure that the image processing models ignore instructions embedded in the images or prompts.
- Capability inventory: The scripts use
curlfor network requests and can read local files through the--fileargument. - Sanitization: User prompts are escaped using
python3 -c 'import json,sys; print(json.dumps(sys.stdin.read().rstrip()))'before being inserted into the JSON payload, which prevents basic JSON injection. - [COMMAND_EXECUTION]: The skill executes local bash scripts that handle user-controlled arguments. Although parameters are cleaned before being sent to the vendor API, the processing of external inputs within a shell environment represents a standard attack surface.
Audit Metadata