qwen-image-2-pro

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: Executes the belt CLI tool to interact with the inference.sh API for image generation. This tool is configured within the allowed-tools section.
  • [EXTERNAL_DOWNLOADS]: References installation documentation and configuration files located in the inference-sh organization's GitHub repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it processes external inputs to generate content.
  • Ingestion points: Accepts user-provided text in the prompt parameter and external image links in the reference_images field (SKILL.md).
  • Boundary markers: No specific delimiters or "ignore" instructions are provided to separate user inputs from the command structure in the provided examples.
  • Capability inventory: The skill utilizes the belt CLI to perform operations based on user input.
  • Sanitization: Input data is passed directly to the CLI tool without explicit sanitization or validation logic shown in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 10:49 PM
Security Audit — agent-trust-hub — qwen-image-2-pro