imagegen
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the execution of local Python scripts, specifically
scripts/image_gen.pyandremove_chroma_key.py, to handle interaction with external APIs and perform image post-processing (such as background removal). - [EXTERNAL_DOWNLOADS]: The skill documentation instructs users to install standard, well-known Python packages (
openai,pillow) via theuvpackage manager and involves network communication with official OpenAI API endpoints. - [CREDENTIALS_UNSAFE]: The skill requires an
OPENAI_API_KEYfor its CLI fallback mode but correctly instructs the user to provide this via environment variables, avoiding the risk of hardcoded credentials. - [PROMPT_INJECTION]: The skill manages potential indirect prompt injection risks through a structured ingestion and normalization workflow.
- Ingestion points: User-provided text prompts and reference images are ingested for processing (documented in
SKILL.md). - Boundary markers: The skill implements a 'Shared prompt schema' that uses explicit labels to structure the user input and separate it from internal instructions.
- Capability inventory: The skill has the capability to write files to the workspace and make network calls via the provided CLI scripts.
- Sanitization: A prompt augmentation and normalization process is used to validate and structure user input before it is passed to the generation model, reducing the surface area for adversarial input.
Audit Metadata