segment-anything-model

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads official pre-trained model checkpoints (ViT-H, ViT-L, ViT-B) from Meta AI's public file server at dl.fbaipublicfiles.com. These are recognized as safe, standard assets for the model's functionality.\n- [REMOTE_CODE_EXECUTION]: The skill instructions provide commands to install the segment-anything and segment-anything-2 libraries directly from the official facebookresearch GitHub repositories. As Meta is a trusted organization, these installations are categorized as safe remote code execution.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted image data through libraries like OpenCV and PIL for segmentation tasks. However, the risk is minimal as the model's capabilities are limited to vision processing (generating masks and coordinates) and do not involve interpreting instructions that could influence the agent's behavior or access sensitive system resources.\n
  • Ingestion points: cv2.imread and Image.open in SKILL.md, and file upload endpoints in the FastAPI example within references/advanced-usage.md.\n
  • Boundary markers: None present in the code examples.\n
  • Capability inventory: Image encoding, mask generation, and polygon conversion. No shell execution, arbitrary file writes, or sensitive network operations are performed on the processed data.\n
  • Sanitization: Standard image preprocessing such as resizing and color space conversion is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — segment-anything-model