higgsfield-marketplace-cards
Fail
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the official command-line interface (CLI) installer from the vendor's GitHub repository.
- [REMOTE_CODE_EXECUTION]: Executes a shell script downloaded from the vendor's repository (
install.sh) to bootstrap the tool environment. - [COMMAND_EXECUTION]: Runs the
higgsfield marketplace-cards createcommand through the Bash tool using arguments derived from user input. - [INDIRECT_PROMPT_INJECTION]: The skill incorporates untrusted user input into shell commands, creating a potential vector for indirect prompt or command injection.
- Ingestion points: User prompts and image file paths are ingested in
SKILL.mdto be used as CLI arguments. - Boundary markers: The skill suggests using double quotes around the
--promptargument, but lacks robust delimiters or escaping instructions for the agent. - Capability inventory: The skill has access to the
Bashtool, allowing for full command execution. - Sanitization: The instructions do not specify any validation or sanitization steps for user-provided strings before they are executed.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/higgsfield-ai/cli/main/install.sh - DO NOT USE without thorough review
Audit Metadata