higgsfield-product-photoshoot

Fail

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to download and execute an installation script for the Higgsfield CLI from the official GitHub repository of the vendor. This is documented as a standard setup procedure for the vendor's tools.
  • Evidence: curl -fsSL https://raw.githubusercontent.com/higgsfield-ai/cli/main/install.sh | sh in SKILL.md.
  • [COMMAND_EXECUTION]: The skill uses the higgsfield CLI tool via Bash to perform authentication checks and trigger image generation jobs.
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts user-provided prompts and images which are then passed to a backend system for processing. This presents a potential surface for indirect injection via untrusted user input.
  • Ingestion points: User-provided descriptions and image files collected during the pre-generation interview (Types A-F in SKILL.md).
  • Boundary markers: None explicitly defined in the CLI command arguments; instructions specify that the backend handles final prompt assembly.
  • Capability inventory: The skill executes shell commands (higgsfield product-photoshoot create) and accesses local files for image uploads.
  • Sanitization: The instructions state that the backend assembles the final prompt, which reduces the risk of direct injection by preventing the agent from generating the final prompt string.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/higgsfield-ai/cli/main/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 26, 2026, 06:12 PM
Security Audit — agent-trust-hub — higgsfield-product-photoshoot