sn-image-base

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided text and image data, which are subsequently passed to external Vision Language Models (VLM) and Language Models (LLM). This creates a vulnerability surface for indirect prompt injection attacks.
  • Ingestion points: The --user-prompt and --images arguments in the sn-image-recognize and sn-text-optimize tools within sn_agent_runner.py.
  • Boundary markers: The skill does not implement delimiters or explicit instructions for the model to ignore embedded commands in the input data.
  • Capability inventory: The skill possesses the ability to make network requests to external APIs via httpx and write files (generated images) to the local filesystem.
  • Sanitization: The skill performs structural integrity validation on downloaded images using the Pillow library and implements a sanitization utility (sanitize_base64_in_data) to prevent large binary blobs from cluttering logs or error reports.
  • [EXTERNAL_DOWNLOADS]: The skill downloads generated image content from remote URLs provided by backend services.
  • Evidence: The download_image function in scripts/sn_image_base/generation/sensenova.py fetches data from URLs provided by the API response.
  • Context: The downloads originate from the CDNs of well-known and configured AI service providers (e.g., SenseNova, OpenAI, Anthropic), which are considered trusted sources in this context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 08:10 AM
Security Audit — agent-trust-hub — sn-image-base