qwen-image-2

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill uses the allowed-tools configuration to limit shell execution specifically to the belt CLI (Bash(belt *)), which follows the principle of least privilege.
  • [EXTERNAL_DOWNLOADS]: The skill references documentation and installation scripts from inference.sh and its associated GitHub repository. These are well-known service resources related to the skill's primary function.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of external image URLs (reference_images) and user prompts for image generation/editing. * Ingestion points: reference_images array and prompt parameter in SKILL.md examples. * Boundary markers: None present in the instructions. * Capability inventory: Executing commands via the belt tool. * Sanitization: The skill documentation does not explicitly detail sanitization of these inputs before they are passed to the CLI tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:14 PM
Security Audit — agent-trust-hub — qwen-image-2