visual-inspection-improvement

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to take and inspect screenshots of external content, which creates a surface for visual prompt injection where malicious instructions could be embedded in the UI/graphics being analyzed.
  • Ingestion points: Screenshots of websites, web applications, game assets, and GUI elements (SKILL.md).
  • Boundary markers: Absent; the skill lacks instructions for the agent to distinguish between design elements and embedded adversarial text/instructions in the images.
  • Capability inventory: The skill workflow assumes the agent can take screenshots and modify source code/files to "make improvements."
  • Sanitization: Absent; there is no validation or filtering of the visual content before the agent interprets it to make code changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:19 PM
Security Audit — agent-trust-hub — visual-inspection-improvement