qwen-image-2-pro

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references downloads for the belt CLI and associated skills (npx skills add belt-sh/cli). These are directed to the official inference.sh platform and its verified GitHub repositories, which is standard for this tool's ecosystem.
  • [COMMAND_EXECUTION]: The skill provides examples of bash commands using the belt CLI. These commands are restricted to the intended purpose of the skill (authenticating and running image generation models) and do not include any arbitrary or suspicious command execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided text for image prompts. While these are processed by the remote AI model, the skill itself does not have local execution capabilities that would allow a prompt injection to affect the user's host system beyond the intended image generation scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:20 PM
Security Audit — agent-trust-hub — qwen-image-2-pro