visual-forge

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill includes a vulnerability surface as it processes external, untrusted data from user-supplied URLs and task descriptions.
  • Ingestion points: User-provided URLs for visual reference capture and task parameters via the {{ARGUMENTS}} placeholder in SKILL.md.
  • Boundary markers: The skill uses descriptive placeholders in handoff templates but lacks strict data/instruction delimiters.
  • Capability inventory: The skill coordinates code implementation, file writes, and interaction with image generation tools via the $forge and $imagegen extensions.
  • Sanitization: No explicit content filtering is documented; however, the workflow enforces a mandatory human approval step (Step 3) after reference capture and before any code-bearing implementation, which serves as a robust human-in-the-loop mitigation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 11:36 AM
Security Audit — agent-trust-hub — visual-forge