higgsfield-generate

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download of the Higgsfield CLI from the vendor's official GitHub repository. This operation is necessary for the skill to interact with the Higgsfield AI services.\n- [REMOTE_CODE_EXECUTION]: A shell script installation method (curl | sh) is used to set up the CLI. This is a standard deployment practice for the vendor's tooling and is directed to their verified repository.\n- [PROMPT_INJECTION]: An automated scan reported a potential jailbreak pattern; however, manual inspection confirms that the skill instructions are benign and focused on model selection, parameter validation, and user experience guidelines.\n- [DATA_EXFILTRATION]: No unauthorized data exfiltration patterns were detected. The skill's data handling (uploading media and fetching product URLs) is restricted to the primary functionality of the Higgsfield generation service.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 03:46 PM