sn-da-image-caption

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The SKILL.md instructions and code examples frequently use subprocess.run to execute the internal scripts/caption.py utility. This is standard behavior for skills that rely on standalone scripts for specialized tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection because it ingests untrusted data from external image files.
  • Ingestion points: The scripts/caption.py script reads local image files and converts their content into text descriptions via a vision model.
  • Boundary markers: The instructions do not define explicit boundary markers or "ignore embedded instructions" delimiters when the vision model's output is processed by the agent.
  • Capability inventory: The agent has the capability to execute the caption.py script, write files to the local system (Excel/CSV exports), and generate visualizations using matplotlib.
  • Sanitization: The parse_markdown_table function in SKILL.md performs basic structure validation but does not sanitize the text content for potential prompt injection patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:38 AM
Security Audit — agent-trust-hub — sn-da-image-caption