digipop-coloring-book-creation

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill's workflow involves ingesting and evaluating image data from various untrusted web sources (e.g., stock sites and community archives). This creates a surface for indirect prompt injection, where malicious instructions or adversarial content visually embedded in the source illustrations could influence the behavior of the vision models during the scoring and quality assurance phases.
  • Ingestion points: Illustrations are downloaded from the web and stored in {bundle_dir}/research/thumbnails/ for analysis by vision-capable agents.
  • Boundary markers: The instructions do not define specific delimiters or instructions to mitigate the risk of interpreting embedded visual data as malicious commands.
  • Capability inventory: The skill has the ability to execute local Python scripts (Pillow), make external API calls (fal.ai), and perform automated uploads to a media gallery via helper scripts.
  • Sanitization: No security-related sanitization or validation of the ingested visual content is described beyond quality scoring.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 09:16 AM
Security Audit — agent-trust-hub — digipop-coloring-book-creation