banner-creator

Pass

Audited by Gen Agent Trust Hub on May 5, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill follows security best practices for handling API credentials by using environment variables and .env files, avoiding hardcoded secrets.
  • [SAFE]: File system operations in scripts/banner_creator.py are protected by path validation and filename sanitization (sanitize_filename) to prevent path traversal vulnerabilities.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as user-supplied strings (message, sub_copy, cta) are interpolated into prompts for the Gemini API.
  • Ingestion points: CLI arguments passed to build_banner_prompt and generate_copy_text in scripts/banner_creator.py.
  • Boundary markers: Absent; the skill uses raw string interpolation or simple double-quote wrapping.
  • Capability inventory: Performs network requests (Gemini API) and file system writes (saving images and markdown files).
  • Sanitization: No content validation or instruction-filtering is implemented for the prompt inputs.
  • [EXTERNAL_DOWNLOADS]: The download_reference_image function in scripts/banner_creator.py uses the requests library to fetch content from user-supplied URLs. While this is a functional requirement for reference images, it creates a potential SSRF (Server-Side Request Forgery) surface.
Audit Metadata
Risk Level
SAFE
Analyzed
May 5, 2026, 08:56 AM
Security Audit — agent-trust-hub — banner-creator