creating-coloring-books

Fail

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: Hardcoded authentication credentials for a Piwigo media gallery hosted at media.delo.sh are present in the instruction set.
  • Evidence: username="delorenj", password="Ittr5eesol" in Phase 6 of SKILL.md.
  • [COMMAND_EXECUTION]: The skill executes local Python scripts and shell commands for image processing, vectorization, and packaging.
  • Evidence: Execution of scripts/coloring-convert, magick for image conversion, and zip for packaging in SKILL.md.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with external services to process images and upload assets.
  • Evidence: Uploads and downloads assets via fal.ai (a well-known AI service) and media.delo.sh (a vendor-controlled resource).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted image data from the web which could theoretically contain malicious instructions for the AI models used in the pipeline.
  • Ingestion points: Captures external image content via Google Images search results and browser screenshots (SKILL.md Phase 1 and 2).
  • Boundary markers: Absent.
  • Capability inventory: Spawns sub-agents (sessions_spawn), executes local scripts, performs file writes, and makes network requests.
  • Sanitization: No sanitization or filtering is applied to the image content before it is processed by the fal-ai/qwen-image-edit-2511 model.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 24, 2026, 04:10 AM
Security Audit — agent-trust-hub — creating-coloring-books