gpt-image

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of the belt CLI tool and other skills from the belt-sh and inference-sh GitHub organizations. These are recognized as legitimate vendor resources associated with the skill's author.
  • [COMMAND_EXECUTION]: It provides instructions for using the belt command-line interface to authenticate and run image generation tasks. The commands follow the expected usage pattern for the service.
  • [PROMPT_INJECTION]: The skill is designed to process user-supplied prompts and external image URLs for generation and editing. While this represents a surface for indirect prompt injection (Category 8), the use of structured JSON for tool inputs provides clear boundary markers, and the behavior is inherent to the skill's primary function of image generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 04:02 PM
Security Audit — agent-trust-hub — gpt-image