article-batch-illustration

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to read and analyze user-provided Markdown content to generate image prompts. This represents a significant attack surface for indirect prompt injection, as malicious instructions hidden within the article's text could influence the generated prompts or the agent's behavior during the analysis phase.
  • Ingestion points: SKILL.md describes reading article content from currently open files or specific paths.
  • Boundary markers: The skill lacks explicit instructions to ignore embedded commands within the ingested article text.
  • Capability inventory: The skill executes Python scripts, performs file writes to Obsidian directories, and makes network requests to the Gemini API.
  • Sanitization: No explicit sanitization or filtering of the article content is described before it is processed by the LLM for prompt generation.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with Google's Generative Language API. While these are well-known services, the skill sends data to and receives generated content from https://generativelanguage.googleapis.com.
  • [COMMAND_EXECUTION]: The skill invokes a local Python script (scripts/generate_image.py) using python3 to handle the image generation logic and file system operations. The script uses the urllib and os modules to interact with the network and save files to the local disk.
  • [CREDENTIALS_UNSAFE]: The SKILL.md file contains placeholders like REMOVED_GEMINI_KEY. While these are not active secrets, the instructions guide the agent to pass these credentials as command-line arguments to the Python script, which is a less secure practice compared to environment variables.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 02:09 AM