media-higgsfield-product

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface where untrusted user input is used to generate prompts for an image model.\n
  • Ingestion points: User-provided product descriptions, style choices, and scene details ingested via the workflow defined in SKILL.md and references/interview.md.\n
  • Boundary markers: The skill lacks explicit sanitization or delimiters (such as XML tags or unique markers) for user-provided text within the final prompt assembly logic in references/modes.md.\n
  • Capability inventory: The skill is capable of triggering image generation and accessing credit/cost information through its core tools, as referenced in the workflow.\n
  • Sanitization: The instructions mandate checking for advertising compliance via moai-seller:commerce-ad-claim-compliance-kr and explicitly forbid using copyrighted or trademarked materials.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 01:41 PM
Security Audit — agent-trust-hub — media-higgsfield-product