qwen-image-2

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references installation guidelines hosted on GitHub (raw.githubusercontent.com) for setting up the required CLI environment.
  • [COMMAND_EXECUTION]: The skill uses the belt CLI tool to perform operations such as model execution, app searching, and authentication.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection as it interpolates user-provided text prompts and external image URLs into commands sent to the Alibaba Qwen models; however, this is the intended primary purpose of the skill and follows standard practices for image generation tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:19 PM
Security Audit — agent-trust-hub — qwen-image-2