gpt-image-2
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill utilizes a template-based system where user-provided descriptions are interpolated into JSON or Markdown structures for prompt engineering. This represents a potential surface for indirect injection if a user provides adversarial text designed to influence the agent's behavior during the prompt construction phase.
- Ingestion points: The
--promptand--promptfilearguments ingenerate.jsandedit.js. - Boundary markers: Absent. User input is directly placed into template variables (e.g.,
{argument name="subject"}). - Capability inventory: The skill has the ability to write files to the local disk and make network requests to arbitrary endpoints via
fetchas defined inscripts/shared.js. - Sanitization: No explicit content filtering or escaping of the user-provided prompt text was observed before interpolation.
- [COMMAND_EXECUTION]: The skill's primary workflow requires the agent to execute several Node.js scripts (
check-mode.js,generate.js,edit.js) to detect the environment, generate images, and save outputs. This is the intended behavior of the skill for local image processing. - [EXTERNAL_DOWNLOADS]: The skill performs network operations to fetch generated images from external API endpoints (typically OpenAI or compatible gateways). It also references various assets, thumbnails, and documentation files hosted on GitHub and the author's dedicated case repository (
mmh1.top).
Audit Metadata