skills/ofoxai/skills/image-edit/Gen Agent Trust Hub

image-edit

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local shell commands using bash to interact with a core dependency script (ofox-image.sh) for image processing and cost estimation.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a processing layer for untrusted user prompts and image files, which are interpolated into commands and API requests.
  • Ingestion points: User instructions for image modifications and local file paths for image inputs (found in SKILL.md).
  • Boundary markers: The instructions recommend a specific two-sentence structure for the prompt but do not provide explicit delimiters or "ignore instructions" guardrails for the processed data.
  • Capability inventory: Shell execution via bash, network communication for API calls (delegated to the core script), and writing edited image files to the local file system.
  • Sanitization: No explicit sanitization or validation logic is defined within the skill instructions for the user-provided prompt text or image content.
  • [DYNAMIC_EXECUTION]: The skill implements a bash loop to dynamically resolve the location of the ofox-image.sh script by searching across multiple potential installation paths at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:58 AM