image-attachment-ingestion

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill contains no executable scripts, binaries, or remote code dependencies. It consists entirely of organizational instructions for the AI agent.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface (Category 8):
  • Ingestion points: The skill processes external image attachments and human-provided context to generate summaries and filenames (SKILL.md).
  • Boundary markers: Instructions do not include specific delimiters or prompts to ignore text embedded in images (e.g., OCR-derived content).
  • Capability inventory: The agent is tasked with writing files to local storage and modifying markdown documents (SKILL.md).
  • Sanitization: There is no requirement for content validation or escaping before data is used to generate filenames or summaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 09:36 AM
Security Audit — agent-trust-hub — image-attachment-ingestion