gemini-image
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command using
curlto interact with an external API. This command includes variables such as the API key and the user-provided prompt, which are interpreted at runtime. - [DATA_EXFILTRATION]: The skill accesses a sensitive file path (
config/secrets.md) to read an API key. This key is then transmitted via a POST request to an external domain (api.apicore.ai). While this is the intended functionality of the tool, it represents a data flow where local secrets are sent to a non-standard third-party service. - [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it processes untrusted user data into a sensitive execution context.
- Ingestion points: User-provided image descriptions and potentially image URLs are accepted as input (SKILL.md).
- Boundary markers: There are no delimiters or boundary markers specified to prevent the user input from escaping the JSON structure or the shell command context.
- Capability inventory: The skill utilizes
curlfor network operations and command execution (SKILL.md). - Sanitization: The instructions do not provide any guidance on escaping special characters or sanitizing the user input before placing it into the
-dpayload of thecurlcommand.
Audit Metadata