byted-seedream-image-generate
Warn
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The script
scripts/seedream_image_generate.pycontains a debug print statement that outputs the full API request headers to standard output. This includes theAuthorizationheader containing the user's API key (extracted from environment variables likeARK_API_KEY). This practice leads to sensitive credential exposure in terminal history, IDE logs, or centralized logging systems. - [PROMPT_INJECTION]: The skill enables an attack surface for indirect prompt injection through the
web_searchtool integrated into the Seedream 5.0-lite model. This could allow malicious content from the internet to influence the agent's behavior. - Ingestion points: External data is ingested through the
web_searchtool invoked inseedream_image_generate.pywhen the--web-searchflag is used. - Boundary markers: Absent. The skill does not employ delimiters or specific instructions to isolate or ignore potentially malicious instructions embedded in the search results.
- Capability inventory: The skill performs outbound network requests via
httpxand handles local file paths for generated image outputs. - Sanitization: None. The skill passes tool outputs directly into the model context without filtering, validation, or escaping.
Audit Metadata