article-batch-illustration
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to read and analyze user-provided Markdown content to generate image prompts. This represents a significant attack surface for indirect prompt injection, as malicious instructions hidden within the article's text could influence the generated prompts or the agent's behavior during the analysis phase.
- Ingestion points:
SKILL.mddescribes reading article content from currently open files or specific paths. - Boundary markers: The skill lacks explicit instructions to ignore embedded commands within the ingested article text.
- Capability inventory: The skill executes Python scripts, performs file writes to Obsidian directories, and makes network requests to the Gemini API.
- Sanitization: No explicit sanitization or filtering of the article content is described before it is processed by the LLM for prompt generation.
- [EXTERNAL_DOWNLOADS]: The skill interacts with Google's Generative Language API. While these are well-known services, the skill sends data to and receives generated content from
https://generativelanguage.googleapis.com. - [COMMAND_EXECUTION]: The skill invokes a local Python script (
scripts/generate_image.py) usingpython3to handle the image generation logic and file system operations. The script uses theurllibandosmodules to interact with the network and save files to the local disk. - [CREDENTIALS_UNSAFE]: The
SKILL.mdfile contains placeholders likeREMOVED_GEMINI_KEY. While these are not active secrets, the instructions guide the agent to pass these credentials as command-line arguments to the Python script, which is a less secure practice compared to environment variables.
Audit Metadata