ai-product-photography

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides a link to installation instructions for the 'belt' CLI hosted on the vendor's official GitHub repository. These instructions are necessary for the skill's primary functionality and are sourced from the vendor's infrastructure.
  • [COMMAND_EXECUTION]: All provided command examples use the 'belt' CLI to interact with cloud-based AI models. The YAML frontmatter restricts the agent's environment to this specific tool using the 'allowed-tools' configuration, which adheres to the principle of least privilege.
  • [DATA_EXFILTRATION]: Network activity is restricted to the vendor's official API domain (inference.sh) for the purpose of image generation and processing. No attempts to access local sensitive files or communicate with unauthorized external servers were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided product names to generate photography prompts. While this represents a data ingestion surface, the risk is minimal as the input is used within structured CLI parameters and targeted at specialized image generation models.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 03:09 AM
Security Audit — agent-trust-hub — ai-product-photography