hand-drawn-infographic-creator

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is configured to ingest untrusted data from external websites via reference search tools and possesses capabilities to write and edit files. This combination creates an attack surface for indirect prompt injection, where malicious instructions embedded in external web content could attempt to influence the agent's file operations or image generation prompts.
  • Ingestion points: The skill uses mcp__firecrawl__*, WebSearch, and WebFetch to gather visual and conceptual references from across the web, as outlined in the workflow sections of SKILL.md and README.md.
  • Capability inventory: The skill is granted Read, Write, and Edit permissions, and can invoke specialized image generation tools (mcp__stability-ai__*, mcp__ideogram__*).
  • Boundary markers: While the instructions guide the AI to apply specific 'style' and 'context' filters to the search results, there are no explicit delimiters or system instructions used to isolate the fetched data from the agent's decision-making logic.
  • Sanitization: No technical sanitization, schema validation, or escaping of the fetched external content is implemented beyond the natural language filtering instructions provided to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 12:23 AM
Security Audit — agent-trust-hub — hand-drawn-infographic-creator