image-to-diagram
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external visual data (images) and uses the extracted text for file creation and platform-specific ingestion commands, creating a potential vector for indirect injection.
- Ingestion points: The agent reads visual diagrams (screenshots, whiteboard photos) provided by the user (SKILL.md).
- Boundary markers: There are no explicit boundary markers or instructions telling the agent to ignore commands or prompts found within the images.
- Capability inventory: The skill instructs the agent to write files to the user's Desktop (~/Desktop/) and execute the /reflex:ingest command (SKILL.md).
- Sanitization: The skill does not implement sanitization or validation to filter out potential instructions found within the processed images.
Audit Metadata