ai-product-photography

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references installation scripts and package names from the inference-sh GitHub organization and npm registry to enable the belt CLI functionality. These are standard dependencies for the skill's stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill allows for the interpolation of user-provided image prompts into shell commands for the belt CLI tool.
  • Ingestion points: User prompt strings in belt app run commands within SKILL.md.
  • Boundary markers: None.
  • Capability inventory: Shell execution restricted to the belt command via the Bash(belt *) tool policy.
  • Sanitization: None identified in the provided instructions.
  • [SAFE]: The skill uses the allowed-tools frontmatter to enforce a least-privilege execution environment, explicitly restricting the agent to the belt CLI and preventing arbitrary command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:14 PM
Security Audit — agent-trust-hub — ai-product-photography