qwen-image-2

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides integration for image generation services and follows standard patterns for CLI-based tool interaction.
  • [EXTERNAL_DOWNLOADS]: Fetches installation guidelines and references other skills from the official inference-sh GitHub repository and the inference.sh domain. These are the service providers for the skill's functionality and are treated as safe sources for these assets.
  • [COMMAND_EXECUTION]: Uses the belt CLI to execute image generation tasks. These commands are scoped to the alibaba/qwen-image-2 application and do not attempt unauthorized file access or privilege escalation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided prompts and image URIs.
  • Ingestion points: Data enters through the --input JSON object in the prompt and reference_images fields.
  • Boundary markers: None identified in the provided templates.
  • Capability inventory: The skill uses the Bash(belt *) tool to run external inference apps.
  • Sanitization: Not explicitly mentioned; however, the skill operates as a standard wrapper for an image generation API where such inputs are expected.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 04:08 PM
Security Audit — agent-trust-hub — qwen-image-2