alt-text-headings

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The instructions in references/image-analysis-workflow.md direct the agent to use terminal commands, such as curl and Invoke-WebRequest, to download images from remote URLs for analysis. This provides a functional command execution surface that could be abused if the agent is influenced by malicious input.\n- [EXTERNAL_DOWNLOADS]: The skill enables the agent to initiate network connections to fetch content from arbitrary external domains identified during the audit process. This bypasses typical network isolation and allows communication with non-whitelisted remote servers.\n- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted data from the user's project, including source code and images.\n
  • Ingestion points: Source files (HTML, CSS, JS, Markdown) and remote image files discovered during the audit.\n
  • Boundary markers: The instructions lack explicit delimiters or safety warnings to prevent the agent from following instructions embedded within the data being analyzed.\n
  • Capability inventory: The skill uses file system reads, vision-based image analysis, and shell commands (curl) for data retrieval.\n
  • Sanitization: There is no mention of sanitizing or validating the content of audited files or image metadata before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 05:59 AM