morpheus-fashion-design

Fail

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The script 'scripts/generate.py' includes a hardcoded Google Gemini API key ('AIzaSyBCa0WCDlc6XYU6ZlwbqLB5D0hyeIuGmqA') as a fallback value.
  • [EXTERNAL_DOWNLOADS]: The skill instructions in 'SKILL.md' direct the agent to clone a model catalog from an external GitHub repository ('https://github.com/PauldeLavallaz/model_management.git') which is not associated with the skill author.
  • [COMMAND_EXECUTION]: The skill uses shell commands for repository management and file operations, and the generation script performs multiple network-based operations.
  • [DATA_EXFILTRATION]: Local image files provided as product and model references are uploaded to the external 'api.comfydeploy.com' service for processing.
  • [PROMPT_INJECTION]: The skill ingests untrusted campaign briefs and target descriptions which are interpolated into API calls without sanitization or boundary markers, creating a surface for indirect prompt injection.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 16, 2026, 01:03 AM
Security Audit — agent-trust-hub — morpheus-fashion-design