image-gen

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @higgsfield/cli package via npm to perform its primary functions. This is a legitimate dependency for the Higgsfield service.
  • [COMMAND_EXECUTION]: The skill uses shell commands to interact with the Higgsfield CLI, including higgsfield account status for verification and higgsfield generate create for core functionality. These are standard operational commands for a CLI-based integration.
  • [PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection as it processes user-provided prompts and reference images. However, it includes internal instructions to the agent to strictly follow layout and color constraints, which helps mitigate accidental instruction following from the data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 06:47 AM
Security Audit — agent-trust-hub — image-gen