creating-coloring-books
Fail
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: Hardcoded authentication credentials for a Piwigo media gallery hosted at
media.delo.share present in the instruction set. - Evidence:
username="delorenj", password="Ittr5eesol"in Phase 6 ofSKILL.md. - [COMMAND_EXECUTION]: The skill executes local Python scripts and shell commands for image processing, vectorization, and packaging.
- Evidence: Execution of
scripts/coloring-convert,magickfor image conversion, andzipfor packaging inSKILL.md. - [EXTERNAL_DOWNLOADS]: The skill interacts with external services to process images and upload assets.
- Evidence: Uploads and downloads assets via
fal.ai(a well-known AI service) andmedia.delo.sh(a vendor-controlled resource). - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted image data from the web which could theoretically contain malicious instructions for the AI models used in the pipeline.
- Ingestion points: Captures external image content via Google Images search results and browser screenshots (
SKILL.mdPhase 1 and 2). - Boundary markers: Absent.
- Capability inventory: Spawns sub-agents (
sessions_spawn), executes local scripts, performs file writes, and makes network requests. - Sanitization: No sanitization or filtering is applied to the image content before it is processed by the
fal-ai/qwen-image-edit-2511model.
Recommendations
- AI detected serious security threats
Audit Metadata