segment-anything-model
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to download model weights and libraries from established external sources.
- Fetches the
segment-anythingandsegment-anything-2libraries directly from Facebook Research's official GitHub repository. - Downloads pre-trained model checkpoints (ViT-H, ViT-L, ViT-B) from
dl.fbaipublicfiles.com, which is a well-known service operated by Meta AI. - These operations target well-known organizations and do not involve piped execution into a shell.
- [COMMAND_EXECUTION]: The documentation includes standard setup commands for a development environment.
- Provides
pip installcommands for necessary Python dependencies liketransformers,torch,opencv-python, andpycocotools. - Provides
wgetcommands to retrieve large model files required for the skill's primary function. - Includes an ONNX export script example for model deployment.
- [INDIRECT_PROMPT_INJECTION]: The skill defines an interface that processes external data, creating a potential attack surface.
- Ingestion points: Processes images via
cv2.imread, FastAPI'sUploadFile, and Gradio'sgr.Image. Also accepts point and box coordinate prompts from users. - Boundary markers: Code examples do not explicitly demonstrate sanitization of image metadata or validation of coordinate bounds beyond basic assertions in the troubleshooting guide.
- Capability inventory: The skill facilitates local file writes (saving masks/annotations) and model downloads.
- Sanitization: Standard for this type of vision task, the vulnerability is inherent to processing complex binary data (images).
Audit Metadata