image-enhancement-suite

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes image files to extract EXIF metadata tags like 'Model', 'Software', and 'LensModel'. Because these strings are sourced from external files and are not sanitized, they present a surface for indirect prompt injection if the agent interprets these strings as instructions or uses them to generate subsequent commands.\n
  • Ingestion points: scripts/image_metadata.py (EXIF data extraction from images).\n
  • Boundary markers: None present; metadata values are returned as raw strings.\n
  • Capability inventory: Extensive file manipulation and writing capabilities across all scripts (PIL and OpenCV operations).\n
  • Sanitization: No escaping or validation is performed on the extracted metadata strings.\n- [DATA_EXFILTRATION]: The scripts/image_metadata.py script specifically targets and extracts GPS coordinates (latitude, longitude, and altitude) from images. While this is the intended purpose of the tool, it exposes sensitive location data to the agent context and generates Google Maps URLs, which constitutes a data exposure risk for users processing personal photos.\n- [EXTERNAL_DOWNLOADS]: The skill relies on the folium library in scripts/image_metadata.py to generate interactive HTML maps. These generated files contain references to external resources, such as Leaflet.js and OpenStreetMap tile servers, which are loaded from third-party Content Delivery Networks (CDNs) when the map is viewed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:52 PM
Security Audit — agent-trust-hub — image-enhancement-suite