edit-image
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/edit.tsutilizes dynamic imports with computed paths to load internal dependency modules likeutils.ts,shared.ts, andproviders/*.tsafter resolving the plugin root directory from the local environment. - [INDIRECT_PROMPT_INJECTION]: The skill accepts natural language prompts to describe image edits, which are then passed to generative AI models. This creates a surface for indirect prompt injection if untrusted data is passed through the prompt parameter.
- Ingestion points: User-provided positional arguments in
scripts/edit.tsfor the edit prompt and image paths. - Boundary markers: No explicit delimiters or instructions are used to separate the user prompt from the underlying model instructions.
- Capability inventory: The skill has capabilities for reading and writing to the local filesystem (images) and performing network requests to AI service providers.
- Sanitization: The input prompt is used directly without sanitization or filtering.
Audit Metadata