higgsfield-generate

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill contains a bootstrap command to install the Higgsfield CLI by downloading and executing a script directly from the vendor's official GitHub repository. This is a standard and expected deployment step for the vendor's ecosystem.
  • [EXTERNAL_DOWNLOADS]: The skill fetches installation scripts and configuration from the official higgsfield-ai organization on GitHub. These references are associated with the skill's primary purpose and originate from a trusted vendor source.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute Higgsfield CLI commands. These commands are used to submit generation jobs, list models, and manage authentication states.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: User-provided text prompts and file paths for media references are ingested through CLI flags in SKILL.md.
  • Boundary markers: There are no explicit boundary markers or "ignore embedded instructions" warnings defined for the user-supplied prompts in the command templates.
  • Capability inventory: The skill has the capability to execute shell commands and perform network operations via the higgsfield CLI tool.
  • Sanitization: No specific input sanitization or validation logic for user-provided prompt strings is described in the skill's static instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 05:52 PM
Security Audit — agent-trust-hub — higgsfield-generate