qwen-image-2-pro

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references installation scripts and documentation from raw.githubusercontent.com/inference-sh/skills/. This is a standard practice for this skill's ecosystem to manage dependencies.
  • [COMMAND_EXECUTION]: The skill provides examples using the belt CLI tool and npx skills add commands. These are intended for setting up the environment and executing the primary function of the skill (image generation).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided prompts to generate images. While prompts are interpolated into CLI and SDK calls, the risk is limited to the output of the image generation service itself, and there are no high-privilege tool capabilities that could be exploited via injection in this context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:22 PM
Security Audit — agent-trust-hub — qwen-image-2-pro