media-higgsfield-product
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface where untrusted user input is used to generate prompts for an image model.\n
- Ingestion points: User-provided product descriptions, style choices, and scene details ingested via the workflow defined in
SKILL.mdandreferences/interview.md.\n - Boundary markers: The skill lacks explicit sanitization or delimiters (such as XML tags or unique markers) for user-provided text within the final prompt assembly logic in
references/modes.md.\n - Capability inventory: The skill is capable of triggering image generation and accessing credit/cost information through its core tools, as referenced in the workflow.\n
- Sanitization: The instructions mandate checking for advertising compliance via
moai-seller:commerce-ad-claim-compliance-krand explicitly forbid using copyrighted or trademarked materials.
Audit Metadata