sn-image-imitate

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's architecture involves orchestrating a three-step pipeline through shell commands executed via a runner script (sn_agent_runner.py). These commands incorporate variables like $TARGET_CONTENT, $LONG_CAPTION, and $LAYOUT_BLUEPRINT_JSON. If the execution environment (e.g., OpenClaw or Hermes) does not apply strict escaping or sanitization when interpolating these variables into the shell environment, it could lead to command injection vulnerabilities, particularly in Step 0 where user input is written to a file using the echo command.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a conduit for processing external data and user-provided descriptions, creating a surface for indirect prompt injection.
  • Ingestion points: Untrusted content enters the system via the reference_image (Step 1) and target_content (Step 0) parameters. The reference image is analyzed by a Vision-Language Model (VLM), and the resulting captions are used in subsequent prompts.
  • Boundary markers: The skill's system prompts (e.g., image_annotate.md and caption_rewrite.md) utilize structural requirements and request specific JSON formats to constrain the AI output. However, they lack explicit instructions to disregard malicious directives that might be embedded within the image data or user descriptions.
  • Capability inventory: The skill utilizes a runner script to invoke VLM, LLM, and Image Generation tools through subprocesses and performs file writing operations to the /tmp directory.
  • Sanitization: The instructions do not specify any validation, filtering, or sanitization steps for the user-provided text or the descriptions extracted from external images before they are passed to other components of the pipeline.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 AM
Security Audit — agent-trust-hub — sn-image-imitate