kernel-image-product
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is text-based prompt generation. Analysis of the SKILL.md and referenced monotone.md files reveals no malicious patterns, unauthorized tool usage, or hidden instructions.
- [DATA_EXFILTRATION]: No network tools (like curl or wget) are requested or used. The only tool allowed is 'Read', which is used locally to access the skill's own reference documentation.
- [COMMAND_EXECUTION]: There are no shell commands, subprocess calls, or privilege escalation attempts detected in the instruction set or the reference files.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-supplied product descriptions to format them into image prompts. While the skill lacks explicit delimiters for user input, the risk is negligible because the skill does not have access to sensitive data or executable tools that could be subverted by a malicious input string.
Audit Metadata