imagegen

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of local Python scripts, specifically scripts/image_gen.py and remove_chroma_key.py, to handle interaction with external APIs and perform image post-processing (such as background removal).
  • [EXTERNAL_DOWNLOADS]: The skill documentation instructs users to install standard, well-known Python packages (openai, pillow) via the uv package manager and involves network communication with official OpenAI API endpoints.
  • [CREDENTIALS_UNSAFE]: The skill requires an OPENAI_API_KEY for its CLI fallback mode but correctly instructs the user to provide this via environment variables, avoiding the risk of hardcoded credentials.
  • [PROMPT_INJECTION]: The skill manages potential indirect prompt injection risks through a structured ingestion and normalization workflow.
  • Ingestion points: User-provided text prompts and reference images are ingested for processing (documented in SKILL.md).
  • Boundary markers: The skill implements a 'Shared prompt schema' that uses explicit labels to structure the user input and separate it from internal instructions.
  • Capability inventory: The skill has the capability to write files to the workspace and make network calls via the provided CLI scripts.
  • Sanitization: A prompt augmentation and normalization process is used to validate and structure user input before it is passed to the generation model, reducing the surface area for adversarial input.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — imagegen