optimize-images
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/optimize-images.tsperforms dynamic loading from computed paths by attempting to resolveresolve-root.tsthrough environment variables and searching local plugin installation directories. This behavior is used to locate internal vendor utilities but involves runtime path calculation. - [COMMAND_EXECUTION]: The skill provides scripts that execute batch file system operations, specifically identifying and overwriting PNG and JPEG files within the project's
public/imagesdirectory. While these operations are the primary purpose of the skill, they represent automated modifications to project assets. - [INDIRECT_PROMPT_INJECTION]: The skill processes external image files, which serves as a potential vector for indirect injection. However, the risk is minimized by explicit instructions to avoid reading the processed binary content into the agent's context window, limiting the attack surface to the processing library itself.
Audit Metadata