photo-content-recognition-curation-expert

Warn

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The QuickPhotoIndexer class in references/photo-indexing.md utilizes pickle.load() and pickle.dump() to manage a local cache file (./photo_cache/photo_index.pkl). Deserializing data with the pickle module is inherently unsafe as it can be used to execute arbitrary code if the cache file is replaced with a malicious payload.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted image files from a user's library and performs content analysis, including text extraction via OCR using pytesseract (documented in references/content-detection.md). This creates an attack surface where instructions embedded in photos (e.g., screenshots of malicious text) could influence the agent's behavior when processed.
  • Ingestion points: Image files processed from the photo library path in references/photo-indexing.md.
  • Boundary markers: Absent; there are no explicit delimiters or warnings for the agent to ignore instructions within the extracted text.
  • Capability inventory: The skill has access to tools for file reading/writing and shell command execution (Bash).
  • Sanitization: Absent; no explicit sanitization or filtering of OCR-extracted content is performed before storage or usage.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 18, 2026, 01:19 PM
Security Audit — agent-trust-hub — photo-content-recognition-curation-expert