image-optimization-engineer

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill focuses on technical implementation of image optimization (Next.js Image, AVIF/WebP, lazy loading, and responsive images). It does not include any unauthorized network requests, credential harvesting, or suspicious shell command patterns.
  • [PROMPT_INJECTION]: The skill processes untrusted code and assets during optimization tasks, creating an inherent attack surface for indirect prompt injection.
  • Ingestion points: Local project files, including component source code and image assets, are read and modified by the agent during optimization workflows (SKILL.md).
  • Boundary markers: Absent. The skill does not instruct the agent on how to distinguish instructions from the data it is processing.
  • Capability inventory: The skill utilizes Read, Write, and Edit file operations, as well as Bash commands limited to npm and npx for installing and running performance utilities.
  • Sanitization: No sanitization or validation logic is specified for the external content processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 07:20 PM
Security Audit — agent-trust-hub — image-optimization-engineer