vision-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection because it processes untrusted image content and extracts text via OCR or UI review without safety boundaries.
  • Ingestion points: Image file paths and URLs are extracted from user messages as described in the Workflow section of SKILL.md.
  • Boundary markers: Absent; the prompts used for ocr and ui-review modes do not include delimiters or instructions for the agent to ignore potentially malicious commands embedded within the image text.
  • Capability inventory: The skill invokes the MiniMax_understand_image tool; no other dangerous capabilities like arbitrary file writing or non-vendor network requests were identified in the skill instructions.
  • Sanitization: No validation, escaping, or filtering of the content extracted from images is described.
  • [EXTERNAL_DOWNLOADS]: The skill provides setup instructions that involve downloading the minimax-coding-plan-mcp package from a public registry. This is a vendor-related resource associated with the skill author.
  • [COMMAND_EXECUTION]: The documentation provides shell commands for multiple environments (OpenCode, Claude Code, Cursor) that utilize uvx to execute the MCP server package.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:59 AM
Security Audit — agent-trust-hub — vision-analysis