skills/b-open-io/gemskills/edit-image/Gen Agent Trust Hub

edit-image

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/edit.ts utilizes dynamic imports with computed paths to load internal dependency modules like utils.ts, shared.ts, and providers/*.ts after resolving the plugin root directory from the local environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts natural language prompts to describe image edits, which are then passed to generative AI models. This creates a surface for indirect prompt injection if untrusted data is passed through the prompt parameter.
  • Ingestion points: User-provided positional arguments in scripts/edit.ts for the edit prompt and image paths.
  • Boundary markers: No explicit delimiters or instructions are used to separate the user prompt from the underlying model instructions.
  • Capability inventory: The skill has capabilities for reading and writing to the local filesystem (images) and performing network requests to AI service providers.
  • Sanitization: The input prompt is used directly without sanitization or filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 10:03 AM