image-utils
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill contains functionality to download image data from external URLs via the
ImageUtils.load_from_urlmethod, which utilizes therequestslibrary. This is a standard feature for image processing utilities to handle remote assets. - [INDIRECT_PROMPT_INJECTION]: The skill exposes a surface for processing untrusted image data from external sources. While it does not process natural language instructions within the images, it possesses the capabilities required for data ingestion.
- Ingestion points:
ImageUtils.loadandImageUtils.load_from_urlinreferences/code-examples/image_utils.pyingest data from URLs, file paths, and base64 strings. - Boundary markers: None identified; the skill treats all input as image data for processing.
- Capability inventory: The skill has the capability to perform network GET requests (
requests.get), create local directories (Path.mkdir), and write files to the local file system (Image.save). - Sanitization: Standard Pillow
Image.openvalidation is used, which ensures data adheres to supported image formats.
Audit Metadata