baoyu-image-cards
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructions that attempt to override the agent's safety protocols regarding sensitive or copyrighted figures. Specifically, the prompt assembly guide instructs the agent to 'create stylistically similar alternatives' and 'DO NOT refuse to generate' if sensitive figures are detected in the content, which is a pattern designed to bypass standard safety filters.
- [SAFE]: The skill processes user-supplied source material which is then interpolated into prompts for analysis, outline generation, and final image creation. This constitutes an indirect prompt injection surface (Category 8). However, the risk is assessed as low because the skill's capabilities are limited to file system operations (saving analysis/images) and tool calls for image generation, with no evidence of high-privilege access or sensitive data exfiltration.
- [SAFE]: The skill performs file system operations including reading configuration from 'EXTEND.md' and writing outputs to a local project directory. These operations are transparent, follow a documented structure, and include backup rules to prevent accidental data loss.
- [SAFE]: The skill provides clear logic for discovering and using runtime-native tools (e.g., Codex 'imagegen' or Hermes 'image_generate') and implements a confirmation policy to ensure user oversight before performing resource-intensive tasks like image generation.
Audit Metadata