skills/frankxai/arcanea/image-to-code/Gen Agent Trust Hub

image-to-code

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to extract text from generated images and use it to guide implementation (Rules 9 and 21). This creates an indirect prompt injection surface where instructions embedded in the generated design could potentially override intended behavior during the implementation phase.
  • Ingestion points: User-provided design prompts and text extracted from generated section images (SKILL.md).
  • Boundary markers: Absent. No explicit instructions are provided to sanitize or ignore instructions found within extracted text.
  • Capability inventory: Image generation and frontend code implementation.
  • Sanitization: Absent. The skill lacks validation steps for text extracted from visual components.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 11:07 AM
Security Audit — agent-trust-hub — image-to-code