slack-gif-creator

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-supplied images as frames or inspiration for GIF creation. This creates a surface for indirect prompt injection where malicious instructions could be embedded in the metadata (e.g., EXIF data) or the content of the uploaded files.
  • Ingestion points: The SKILL.md file (under 'Working with User-Uploaded Images') instructs the agent to load and work with user-provided images using the PIL library.
  • Boundary markers: The instructions do not define specific delimiters or "ignore embedded instructions" warnings for the external image data being processed.
  • Capability inventory: The skill possesses file writing capabilities through core/gif_builder.py, which uses the imageio library to save GIFs to the local file system.
  • Sanitization: There is no mention of stripping metadata, validating image content, or sanitizing inputs before processing them into frames.
  • [METADATA_POISONING]: The _meta.json file contains tags that are inconsistent with the skill's actual implementation. Specifically, it includes "javascript" and "web" tags for a skill that is implemented entirely in Python and focused on image manipulation. While likely a result of template reuse, such inaccuracies can mislead users or automated systems about the skill's execution environment and requirements.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:09 AM
Security Audit — agent-trust-hub — slack-gif-creator