upload
Pass
Audited by Gen Agent Trust Hub on May 10, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses standard shell commands (
grep) inSKILL.md(Step 3) to inspect the local project structure for existing upload-related libraries (likemulterandsharp) and virus scanning configurations (clamav). These are benign discovery actions used to align the agent's actions with the current codebase. - [SAFE]: The skill is designed with a strong security posture, explicitly requiring server-side validation of magic bytes to prevent file-type spoofing and mandating the use of virus scanners before files are served.
- [SAFE]: The instructions include privacy-preserving measures, such as automatically stripping EXIF metadata from all processed images using the
sharplibrary. - [SAFE]: While the skill encourages high autonomy with instructions to "Loop autonomously," it does not contain any commands that attempt to bypass platform safety filters, escalate privileges, or exfiltrate sensitive data.
Audit Metadata