qwen-image-2-pro

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill contains no malicious code, persistent mechanisms, or credential theft attempts. All commands and capabilities are strictly aligned with the intended purpose of image generation via the Alibaba Qwen model.\n- [EXTERNAL_DOWNLOADS]: The skill references installation instructions and additional components from the service provider's official GitHub organization and domain. This is standard and expected behavior for a tool-based skill.\n
  • Evidence: Installation links pointing to github.com/inference-sh and documentation at inference.sh.\n- [PROMPT_INJECTION]: The skill provides a surface for user-defined prompts to be processed by an external image generation model. While this creates a point of entry for indirect instructions, it is inherent to the skill's primary function and does not contain behavior to bypass safety filters.\n
  • Evidence: Examples demonstrating the use of the prompt field in the belt CLI and Python SDK.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 06:32 PM
Security Audit — agent-trust-hub — qwen-image-2-pro