iblai-marketing-image
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use standard system utilities including
curl,cwebp,mogrify, andjpegoptimfor image processing and website analysis.\n- [EXTERNAL_DOWNLOADS]: Contains references to official documentation and APIs for well-known services including Google Gemini, OpenAI, Vercel, and Ideogram.\n- [PROMPT_INJECTION]: The skill provides a workflow that involves fetching content from user-specified URLs viacurlto identify images. This processes untrusted external data which could contain malicious instructions.\n - Ingestion points: External website content fetched via
curlinSKILL.md.\n - Boundary markers: None provided to isolate external content from instructions.\n
- Capability inventory: Subprocess execution for shell commands (
curl,cwebp,mogrify, etc.).\n - Sanitization: No explicit sanitization or validation of the fetched content is described.
Audit Metadata