byted-seedream-image-generate

Warn

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The script scripts/seedream_image_generate.py contains a debug print statement that outputs the full API request headers to standard output. This includes the Authorization header containing the user's API key (extracted from environment variables like ARK_API_KEY). This practice leads to sensitive credential exposure in terminal history, IDE logs, or centralized logging systems.
  • [PROMPT_INJECTION]: The skill enables an attack surface for indirect prompt injection through the web_search tool integrated into the Seedream 5.0-lite model. This could allow malicious content from the internet to influence the agent's behavior.
  • Ingestion points: External data is ingested through the web_search tool invoked in seedream_image_generate.py when the --web-search flag is used.
  • Boundary markers: Absent. The skill does not employ delimiters or specific instructions to isolate or ignore potentially malicious instructions embedded in the search results.
  • Capability inventory: The skill performs outbound network requests via httpx and handles local file paths for generated image outputs.
  • Sanitization: None. The skill passes tool outputs directly into the model context without filtering, validation, or escaping.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — byted-seedream-image-generate