higgsfield-generate
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the download of the Higgsfield CLI from the vendor's official GitHub repository. This operation is necessary for the skill to interact with the Higgsfield AI services.\n- [REMOTE_CODE_EXECUTION]: A shell script installation method (curl | sh) is used to set up the CLI. This is a standard deployment practice for the vendor's tooling and is directed to their verified repository.\n- [PROMPT_INJECTION]: An automated scan reported a potential jailbreak pattern; however, manual inspection confirms that the skill instructions are benign and focused on model selection, parameter validation, and user experience guidelines.\n- [DATA_EXFILTRATION]: No unauthorized data exfiltration patterns were detected. The skill's data handling (uploading media and fetching product URLs) is restricted to the primary functionality of the Higgsfield generation service.
Audit Metadata