ai-artist
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes local Python scripts (
search.py,prompt_builder.py) to manage and query its prompt database. These scripts perform standard text processing and local file I/O operations within the skill's own directory structure. - [INDIRECT_PROMPT_INJECTION]: The skill acts as an intermediary for prompt construction, taking user keywords to retrieve templates from a local CSV database. It explicitly includes defensive documentation on jailbreak prevention, boundary markers (using XML tags), and safety filtering, demonstrating a security-conscious design for handling untrusted data.
- [DATA_EXPOSURE]: All data access is restricted to the skill's internal
data/directory, which contains curated CSV files for prompts, styles, and platform-specific syntax. No sensitive system files or credentials are accessed. - [REMOTE_CODE_EXECUTION]: The skill contains no network-enabled code, remote downloads, or dynamic execution patterns (like
evalorexec). It relies entirely on local assets and a pre-configured environment.
Audit Metadata