image-gen
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
@higgsfield/clipackage via npm to perform its primary functions. This is a legitimate dependency for the Higgsfield service. - [COMMAND_EXECUTION]: The skill uses shell commands to interact with the Higgsfield CLI, including
higgsfield account statusfor verification andhiggsfield generate createfor core functionality. These are standard operational commands for a CLI-based integration. - [PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection as it processes user-provided prompts and reference images. However, it includes internal instructions to the agent to strictly follow layout and color constraints, which helps mitigate accidental instruction following from the data.
Audit Metadata