videoagent-image-studio
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill operates via a Node.js script (
tools/generate.js) that is invoked by the agent to perform image generation and manipulation tasks. - [EXTERNAL_DOWNLOADS]: The script communicates with a hosted proxy at
https://image-gen-proxy.vercel.appto obtain temporary access tokens and to submit image generation requests. These network operations are necessary for the skill's core functionality and target a well-known hosting platform. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes user-provided prompts and transmits them to external image generation models.
- Ingestion points: User prompts are captured and passed as command-line arguments to the
generate.jsscript inSKILL.md. - Boundary markers: No specific delimiters or "ignore instructions" warnings are utilized when interpolating the prompt.
- Capability inventory: The skill has network access via the
fetchAPI to communicate with the proxy service. - Sanitization: There is no evidence of prompt sanitization or filtering before the data is sent to the remote API.
Audit Metadata