AI Image Generation & Editor — Nanobanana, GPT Image, ComfyUI

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill is configured to execute code from the NPM registry via npx -y meigen@1.2.12 to install and run the MCP server.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection.
  • Ingestion points: Tools like search_gallery and get_inspiration retrieve data from the meigen.ai backend.
  • Boundary markers: No specific delimiters or warnings are provided to prevent the agent from following instructions embedded within the gallery content.
  • Capability inventory: The skill possesses capabilities to make network calls for image generation and write to local configuration files.
  • Sanitization: There are no instructions for sanitizing or validating the content received from the remote gallery before it enters the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 01:44 AM
Security Audit — agent-trust-hub — AI Image Generation & Editor — Nanobanana, GPT Image, ComfyUI