sn-infographic
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill relies exclusively on vendor-provided tools (sn-image-base) and internal API endpoints. Authentication is handled through standard environment variables, and no hardcoded credentials or untrusted third-party dependencies were found.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user prompts as the primary input for infographic generation. However, it implements a comprehensive validation strategy including a mandatory 'Step 1' evaluation of the prompt's structural information and a 'Step 3' review loop where a Vision Language Model (VLM) checks the generated image for violations of design and content rules. This architecture significantly mitigates the risk of adversarial input affecting the agent's behavior or output quality.
- [COMMAND_EXECUTION]: The skill's instructions involve the execution of shell commands to call internal helper scripts. It demonstrates secure development practices by using file paths for data ingestion (e.g., --user-prompt-path) in complex steps, which avoids potential command injection vulnerabilities that could arise from passing unsanitized user strings directly to the command line.
Audit Metadata