image-key

Pass

Audited by Gen Agent Trust Hub on Mar 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns detected. The skill uses curl to interact with the Lab Nocturne API to fetch an API key, which is consistent with its stated purpose.
  • [SAFE]: Analysis of indirect prompt injection surface: (1) Ingestion points: JSON response from images.labnocturne.com. (2) Boundary markers: None. (3) Capability inventory: curl command execution. (4) Sanitization: None. The skill presents the API key and messages directly to the user; this surface is inherent to the skill's function and is evaluated as safe.
  • [SAFE]: No signs of obfuscation, hardcoded credentials, or persistence mechanisms were found in the skill metadata or instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 20, 2026, 12:30 AM
Security Audit — agent-trust-hub — image-key