photo-composition-critic

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes Python scripts in references/analysis-scripts.md intended for execution via the Bash tool. These scripts use standard libraries such as NumPy, Pillow, and CLIP to perform legitimate image analysis tasks, including visual weight calculation, centroid detection, and Rule of Thirds alignment.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection because it processes untrusted data from local images and external web search results.
  • Ingestion points: Local image files provided to analysis tools and search result snippets from the mcp__firecrawl__firecrawl_search tool.
  • Capability inventory: The skill utilizes the Bash tool for script execution and Write/Edit tools for file operations.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded content were found in the prompt templates.
  • Sanitization: No specific sanitization or filtering logic is implemented for the data ingested from external sources.
  • [EXTERNAL_DOWNLOADS]: The Python implementations in references/analysis-scripts.md utilize clip.load(), which downloads pre-trained machine learning weights from well-known sources (OpenAI/GitHub repositories) to facilitate aesthetic scoring.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:34 PM
Security Audit — agent-trust-hub — photo-composition-critic