gimp-inkscape

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous examples for the agent to use Bash commands to execute image processing tasks locally using GIMP, Inkscape, ImageMagick, and FFmpeg.
  • [EXTERNAL_DOWNLOADS]: The documentation suggests the optional installation of the rembg Python package and provides a link to the well-known Real-ESRGAN GitHub repository for AI upscaling functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates processing external files (images and PDFs), which establishes a standard surface for indirect prompt injection if those files contain malicious instructions or specially crafted metadata.
  • Ingestion points: Local image and PDF files processed via CLI tools as described in SKILL.md.
  • Boundary markers: None present in the provided instruction examples.
  • Capability inventory: Shell command execution for multiple binary tools (convert, identify, ffmpeg, etc.).
  • Sanitization: The examples show direct usage of filenames in shell commands without explicit sanitization logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 05:14 PM
Security Audit — agent-trust-hub — gimp-inkscape