gpt-image-2-gen
Warn
Audited by Snyk on Aug 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required runtime workflow is the user/agent-provided prompt and optional
--imagereference URLs passed intoscripts/gpt-image-gen.sh, where the script builds and sendsprompt/image_urlsinto the generation request and then polls task results forIMAGE_URL=outputs.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill's install instructions tell agents to fetch and run remote code (e.g., git clone / openclaw install) from https://github.com/EvoLinkAI/gpt-image-2-gen-skill (and the .git variant), which will download and execute external code at runtime.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata