imagegen-glyph-mosaic

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill consists solely of markdown instructions and YAML configuration files. There are no executable scripts, binaries, or source code files included in the package, which prevents direct execution of malicious logic from the skill itself.- [PROMPT_INJECTION]: The skill workflow involves processing external user data, creating a potential surface for indirect prompt injection.
  • Ingestion points: Reference images provided by the user are analyzed via the view_image tool in SKILL.md.
  • Boundary markers: The agent is instructed to explicitly label inputs as 'style references only' and to separate observed evidence from inference to maintain clear context boundaries.
  • Capability inventory: The skill utilizes image analysis, image generation, and local workspace file-writing capabilities.
  • Sanitization: Step 5 of the workflow requires the agent to validate that the output contains no meaningful sentences, logos, or watermarks, which serves as a mitigation against the rendering of unintended or injected content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 03:18 AM
Security Audit — agent-trust-hub — imagegen-glyph-mosaic