vision-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection because it processes untrusted image content and extracts text via OCR or UI review without safety boundaries.
- Ingestion points: Image file paths and URLs are extracted from user messages as described in the Workflow section of
SKILL.md. - Boundary markers: Absent; the prompts used for
ocrandui-reviewmodes do not include delimiters or instructions for the agent to ignore potentially malicious commands embedded within the image text. - Capability inventory: The skill invokes the
MiniMax_understand_imagetool; no other dangerous capabilities like arbitrary file writing or non-vendor network requests were identified in the skill instructions. - Sanitization: No validation, escaping, or filtering of the content extracted from images is described.
- [EXTERNAL_DOWNLOADS]: The skill provides setup instructions that involve downloading the
minimax-coding-plan-mcppackage from a public registry. This is a vendor-related resource associated with the skill author. - [COMMAND_EXECUTION]: The documentation provides shell commands for multiple environments (OpenCode, Claude Code, Cursor) that utilize
uvxto execute the MCP server package.
Audit Metadata