bfl-api
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a workflow that accepts user-provided text prompts and image URLs for processing by an external API. This constitutes a standard injection surface for generative AI tools.
- Ingestion points:
promptandinput_imageparameters in request payloads withinSKILL.md,python-client.py, andtypescript-client.ts. - Boundary markers: The skill does not explicitly use delimiters for prompts, relying on the API provider's internal safety controls.
- Capability inventory: Includes shell command execution (cURL), network operations (requests, fetch, aiohttp, axios), and local file system writes for image downloads.
- Sanitization: Validates image dimensions (multiples of 16, 4MP limit) and exposes the API's
safety_toleranceparameter. - [SAFE]: Secret management instructions recommend industry-standard practices, such as utilizing environment variables and
.envfiles combined with.gitignoreto prevent accidental credential leakage. - [SAFE]: The webhook implementation guides prioritize security by providing code examples for HMAC-SHA256 signature verification using
hmac.compare_digestin Python andcrypto.timingSafeEqualin TypeScript. - [SAFE]: Network operations are directed towards legitimate API endpoints (api.bfl.ai) and reputable cloud infrastructure (bfldeliveryprod.blob.core.windows.net) for asset delivery.
Audit Metadata