skills/halt-catch-fire/skills/p-image/Gen Agent Trust Hub

p-image

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of external components, specifically the belt CLI (npx skills add belt-sh/cli) and other related skills from the inference-sh organization. These resources are from a well-known service provider and are necessary for the skill's intended functionality.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute belt commands to run AI models on a remote infrastructure. These commands include belt login for authentication and belt app run for initiating image generation tasks.
  • [PROMPT_INJECTION]: The skill processes user-supplied text prompts and image URLs through the belt CLI. While this represents a surface for indirect prompt injection (where instructions could be hidden in external images or prompts), this is a standard aspect of generative AI tools and is handled here through structured JSON inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 03:53 PM
Security Audit — agent-trust-hub — p-image