higgsfield-soul-id
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides an installation command that downloads and executes a shell script (
install.sh) from the vendor's official GitHub repository (higgsfield-ai/cli). This is a one-time bootstrap operation to ensure the requiredhiggsfieldCLI is available on the system path. - [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to perform operations such as user authentication (higgsfield auth login), checking account status, and executing the core Soul training commands. All commands are standard for the intended use case. - [EXTERNAL_DOWNLOADS]: The skill fetches the
install.shscript from the author's public repository. As this is a vendor-owned resource used for legitimate installation, it is considered safe in this context. - [INDIRECT_PROMPT_INJECTION]: The skill accepts user-supplied data, including character names and local file paths for photos, which are interpolated into CLI commands. While this creates a standard attack surface for local command execution, the skill implements basic quoting for character names to mitigate common injection issues.
Audit Metadata