grant-figure-qa
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: Uses system utilities like
findandidentifyto locate and inspect image files. These operations are restricted to the local filesystem and serve the skill's primary purpose.\n- [COMMAND_EXECUTION]: Executes a localized Python script using thePillowlibrary to extract image resolution and dimensions. This is a common and safe practice for programmatic image analysis.\n- [DATA_EXFILTRATION]: No network communication or data exfiltration patterns were observed. The skill explicitly operates as a read-only auditor.\n- [PROMPT_INJECTION]: The skill contains no instructions designed to override agent constraints or bypass safety filters.\n- [SAFE]: The procedure for configuring subagents involves standard file placement for CLI tool extensions and does not introduce security risks.
Audit Metadata