ip-as-logo

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of natural language instructions and image generation prompts. It does not include any scripts, binaries, or automated installation steps that run during agent execution.
  • [PROMPT_INJECTION]: The skill ingests data from the local workspace (such as README files, product documentation, and manifests) to customize mascot designs. While this presents an indirect prompt injection surface, the risk is negligible as the skill only possesses image generation capabilities, meaning external content can only influence the visual style of the generated mascot rather than triggering malicious actions.
  • Ingestion points: SKILL.md workflow step 2 (workspace README, product docs, manifests, design tokens).
  • Boundary markers: None identified.
  • Capability inventory: Limited to image generation tools.
  • Sanitization: None identified.
  • [EXTERNAL_DOWNLOADS]: The documentation mentions an external website (ipaslogo.com) and a CLI installation command (npx skills), but these are instructions for the user to set up the skill and are not executed autonomously by the AI agent during task performance.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 04:12 PM
Security Audit — agent-trust-hub — ip-as-logo