image-enhancement-suite
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes image files to extract EXIF metadata tags like 'Model', 'Software', and 'LensModel'. Because these strings are sourced from external files and are not sanitized, they present a surface for indirect prompt injection if the agent interprets these strings as instructions or uses them to generate subsequent commands.\n
- Ingestion points:
scripts/image_metadata.py(EXIF data extraction from images).\n - Boundary markers: None present; metadata values are returned as raw strings.\n
- Capability inventory: Extensive file manipulation and writing capabilities across all scripts (PIL and OpenCV operations).\n
- Sanitization: No escaping or validation is performed on the extracted metadata strings.\n- [DATA_EXFILTRATION]: The
scripts/image_metadata.pyscript specifically targets and extracts GPS coordinates (latitude, longitude, and altitude) from images. While this is the intended purpose of the tool, it exposes sensitive location data to the agent context and generates Google Maps URLs, which constitutes a data exposure risk for users processing personal photos.\n- [EXTERNAL_DOWNLOADS]: The skill relies on thefoliumlibrary inscripts/image_metadata.pyto generate interactive HTML maps. These generated files contain references to external resources, such as Leaflet.js and OpenStreetMap tile servers, which are loaded from third-party Content Delivery Networks (CDNs) when the map is viewed.
Audit Metadata