chapter-image-enhancer

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads image metadata and binary files from well-known, trusted services including the Wikimedia API and various US Federal Government domains (NASA, NOAA, USGS, USDA, EPA). These operations are consistent with the skill's stated purpose of sourcing freely-licensed educational imagery.
  • [COMMAND_EXECUTION]: Instructs the agent to execute mkdocs build. This is a standard operation for documentation workflows to verify that local file changes and image insertions are correctly rendered by the static site generator.
  • [DATA_EXFILTRATION]: No patterns of data exfiltration were detected. The network operations are limited to downloading public assets and do not involve accessing or transmitting sensitive user data, environment variables, or credentials.
  • [PROMPT_INJECTION]: No evidence of prompt injection or attempts to bypass safety filters was found. The instructions are focused entirely on content enhancement and license compliance.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection as it processes external content (filenames and metadata from Wikipedia) and interpolates them into local Markdown files. However, the risk is minimal as the skill includes strict formatting rules for captions and attributions, and the processed data is generally low-risk metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 01:28 PM
Security Audit — agent-trust-hub — chapter-image-enhancer