minecraft-model
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute local scripts to interface with external services.
- Evidence: Use of
node scripts/imagine.jsto process design prompts and manage session-based image generation. - [PROMPT_INJECTION]: The skill incorporates specific instructional templates and processes external inputs, creating a surface for potential behavior modification.
- Evidence: Includes role-play prompts for sub-tasks (e.g., 'Role: Expert AI Image Generator') which, while task-specific, define alternate objectives for the agent's workflow.
- Data Ingestion: The skill ingests user-provided text descriptions and evaluates outputs from an external image model, presenting a surface for indirect prompt injection. This is mitigated by instructions for the agent and user to review generated designs before proceeding to the modeling phase.
Audit Metadata