higgsfield-gpt-image-2
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The analyzed files (SKILL.md, reference-sheet-workflow.md, static-ads-workflow.md) contain only markdown-based instructions, prompt templates, and workflow descriptions. There is no evidence of executable scripts, binaries, or automated network operations.
- [PROMPT_INJECTION]: The skill uses highly structured formats (JSON, Prose) for prompting. No bypass instructions, safety filter overrides, or malicious role-play patterns were detected. The instructions focus on layout precision and visual fidelity.
- [DATA_EXFILTRATION]: No hardcoded credentials, sensitive environment variable access, or unauthorized network requests were found. While the documentation describes a workflow for fetching product pages, the skill itself does not implement or provide the tools to perform these network operations.
- [EXTERNAL_DOWNLOADS]: The skill mentions external tools and models (Nano Banana Pro, Soul Cinema, GPT Image 2.0), but does not attempt to download or execute remote code. It explicitly states that certain helper scripts mentioned in the source material are not included in this skill.
Audit Metadata