sn-image-base
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided text and image data, which are subsequently passed to external Vision Language Models (VLM) and Language Models (LLM). This creates a vulnerability surface for indirect prompt injection attacks.
- Ingestion points: The
--user-promptand--imagesarguments in thesn-image-recognizeandsn-text-optimizetools withinsn_agent_runner.py. - Boundary markers: The skill does not implement delimiters or explicit instructions for the model to ignore embedded commands in the input data.
- Capability inventory: The skill possesses the ability to make network requests to external APIs via
httpxand write files (generated images) to the local filesystem. - Sanitization: The skill performs structural integrity validation on downloaded images using the Pillow library and implements a sanitization utility (
sanitize_base64_in_data) to prevent large binary blobs from cluttering logs or error reports. - [EXTERNAL_DOWNLOADS]: The skill downloads generated image content from remote URLs provided by backend services.
- Evidence: The
download_imagefunction inscripts/sn_image_base/generation/sensenova.pyfetches data from URLs provided by the API response. - Context: The downloads originate from the CDNs of well-known and configured AI service providers (e.g., SenseNova, OpenAI, Anthropic), which are considered trusted sources in this context.
Audit Metadata