higgsfield-generate
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill contains a bootstrap command to install the Higgsfield CLI by downloading and executing a script directly from the vendor's official GitHub repository. This is a standard and expected deployment step for the vendor's ecosystem.
- [EXTERNAL_DOWNLOADS]: The skill fetches installation scripts and configuration from the official higgsfield-ai organization on GitHub. These references are associated with the skill's primary purpose and originate from a trusted vendor source.
- [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute Higgsfield CLI commands. These commands are used to submit generation jobs, list models, and manage authentication states.
- [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: User-provided text prompts and file paths for media references are ingested through CLI flags in SKILL.md.
- Boundary markers: There are no explicit boundary markers or "ignore embedded instructions" warnings defined for the user-supplied prompts in the command templates.
- Capability inventory: The skill has the capability to execute shell commands and perform network operations via the higgsfield CLI tool.
- Sanitization: No specific input sanitization or validation logic for user-provided prompt strings is described in the skill's static instructions.
Audit Metadata