image-generation
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill includes instructions that process external data, creating a surface for indirect prompt injection. * Ingestion points: Library custom instructions mentioned in SKILL.md and user-provided originalPrompt text. * Boundary markers: None explicitly defined in the instructions to isolate untrusted data from the agent's core logic. * Capability inventory: The skill uses image generation, audit log access, and session management tools. * Sanitization: No specific validation or escaping of external inputs is described.
- [SAFE]: No other security issues were identified. The skill does not contain obfuscated content, hardcoded credentials, or remote code execution patterns, and its behavior is consistent with its stated purpose.
Audit Metadata