sn-da-image-caption
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
SKILL.mdinstructions and code examples frequently usesubprocess.runto execute the internalscripts/caption.pyutility. This is standard behavior for skills that rely on standalone scripts for specialized tasks. - [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection because it ingests untrusted data from external image files.
- Ingestion points: The
scripts/caption.pyscript reads local image files and converts their content into text descriptions via a vision model. - Boundary markers: The instructions do not define explicit boundary markers or "ignore embedded instructions" delimiters when the vision model's output is processed by the agent.
- Capability inventory: The agent has the capability to execute the
caption.pyscript, write files to the local system (Excel/CSV exports), and generate visualizations usingmatplotlib. - Sanitization: The
parse_markdown_tablefunction inSKILL.mdperforms basic structure validation but does not sanitize the text content for potential prompt injection patterns.
Audit Metadata