iblai-marketing-image

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard system utilities including curl, cwebp, mogrify, and jpegoptim for image processing and website analysis.\n- [EXTERNAL_DOWNLOADS]: Contains references to official documentation and APIs for well-known services including Google Gemini, OpenAI, Vercel, and Ideogram.\n- [PROMPT_INJECTION]: The skill provides a workflow that involves fetching content from user-specified URLs via curl to identify images. This processes untrusted external data which could contain malicious instructions.\n
  • Ingestion points: External website content fetched via curl in SKILL.md.\n
  • Boundary markers: None provided to isolate external content from instructions.\n
  • Capability inventory: Subprocess execution for shell commands (curl, cwebp, mogrify, etc.).\n
  • Sanitization: No explicit sanitization or validation of the fetched content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 01:37 PM
Security Audit — agent-trust-hub — iblai-marketing-image