travel-collage-postcard

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a prompt engineering framework for generating descriptive text. It does not contain any executable scripts, attempts at privilege escalation, persistence mechanisms, or unauthorized data access. The use of external tools is restricted to information gathering for factual accuracy.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it incorporates data from user inputs and external search results (e.g., coordinates and landmarks) into its output. However, the risk is assessed as safe because the agent's capabilities are limited to text generation, and the output format is strictly controlled, preventing malicious instructions in source data from executing dangerous operations.
  • Ingestion points: User-provided city names and themes, as well as real-time search engine results used for fact-checking (SKILL.md).
  • Boundary markers: Not present; the skill merges external information directly into the prompt structure.
  • Capability inventory: Limited to text-based prompt generation for image models; no file system write access or shell execution tools are enabled.
  • Sanitization: The instructions focus on factual verification rather than content sanitization, but the output constraint (‘output only the prompt’) limits the impact of potential injections.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 04:12 AM
Security Audit — agent-trust-hub — travel-collage-postcard