higgsfield-product-photoshoot
Fail
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to download and execute an installation script for the Higgsfield CLI from the official GitHub repository of the vendor. This is documented as a standard setup procedure for the vendor's tools.
- Evidence:
curl -fsSL https://raw.githubusercontent.com/higgsfield-ai/cli/main/install.sh | shinSKILL.md. - [COMMAND_EXECUTION]: The skill uses the
higgsfieldCLI tool via Bash to perform authentication checks and trigger image generation jobs. - [INDIRECT_PROMPT_INJECTION]: The skill accepts user-provided prompts and images which are then passed to a backend system for processing. This presents a potential surface for indirect injection via untrusted user input.
- Ingestion points: User-provided descriptions and image files collected during the pre-generation interview (Types A-F in
SKILL.md). - Boundary markers: None explicitly defined in the CLI command arguments; instructions specify that the backend handles final prompt assembly.
- Capability inventory: The skill executes shell commands (
higgsfield product-photoshoot create) and accesses local files for image uploads. - Sanitization: The instructions state that the backend assembles the final prompt, which reduces the risk of direct injection by preventing the agent from generating the final prompt string.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/higgsfield-ai/cli/main/install.sh - DO NOT USE without thorough review
Audit Metadata