generate-image

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a clear and restricted set of instructions for using the RunComfy MCP tools to generate and edit images.
  • [CREDENTIALS_UNSAFE]: The skill implements a proactive security measure by explicitly instructing the agent: "Never request an API token in chat or add one to a file." This prevents common credential harvesting attacks.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves processing user-provided text prompts and external image URLs. This ingestion of external data is standard for the intended task of image generation and is managed through structured tool schemas rather than direct prompt interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:19 PM
Security Audit — agent-trust-hub — generate-image