avatar-portrait

Pass

Audited by Gen Agent Trust Hub on Mar 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is composed of instructional markdown and prompt templates. It does not include executable code, scripts, or commands that interact with the host system or network.
  • [PROMPT_INJECTION]: The skill uses template interpolation for user-provided styles, which is an indirect prompt injection surface. Evidence Chain: (1) Ingestion point: User input field '[style requested by user]' in SKILL.md. (2) Boundary markers: Template uses markdown headers to separate style requirements. (3) Capability inventory: Restricted to image generation tool calls; no file-system or network access. (4) Sanitization: Relies on model-level safeguards and prompt structure. The risk is minimal and consistent with the intended functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 24, 2026, 07:50 AM