gemini-image

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command using curl to interact with an external API. This command includes variables such as the API key and the user-provided prompt, which are interpreted at runtime.
  • [DATA_EXFILTRATION]: The skill accesses a sensitive file path (config/secrets.md) to read an API key. This key is then transmitted via a POST request to an external domain (api.apicore.ai). While this is the intended functionality of the tool, it represents a data flow where local secrets are sent to a non-standard third-party service.
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it processes untrusted user data into a sensitive execution context.
    • Ingestion points: User-provided image descriptions and potentially image URLs are accepted as input (SKILL.md).
    • Boundary markers: There are no delimiters or boundary markers specified to prevent the user input from escaping the JSON structure or the shell command context.
    • Capability inventory: The skill utilizes curl for network operations and command execution (SKILL.md).
    • Sanitization: The instructions do not provide any guidance on escaping special characters or sanitizing the user input before placing it into the -d payload of the curl command.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 02:10 AM