image-edit
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the use of the
runcomfyCLI tool to execute image editing tasks. It provides templates for passing instructions and external image URLs to the service via command-line arguments. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes remote image content provided by users, which can contain adversarial instructions targeting the AI model.
- Ingestion points: The skill accepts external HTTPS URLs in fields such as
image_urls,images,image, andmask_imageacross its various routing options inSKILL.md. - Boundary markers: While the skill uses structured JSON to organize CLI inputs, the models themselves process the unstructured pixel data of the images where injections may reside.
- Capability inventory: The skill executes the
runcomfyCLI and performs file writing to a user-specified local directory. - Sanitization: The skill documentation acknowledges the risk of image-based prompt injection but does not provide mechanisms for sanitizing the visual content of the user-provided images.
Audit Metadata