image-portrait

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate tool for portrait generation and does not contain malicious code or patterns. It correctly utilizes an internal proxy for API communication.
  • [DATA_EXFILTRATION]: The script reads local files for the purpose of image generation. It includes a validation step that checks for supported image extensions (.jpg, .jpeg, .png, .webp, .bmp), which prevents the tool from being used to exfiltrate sensitive text-based configuration or credential files. The network transmission is directed to the well-known fal.ai service.
  • [EXTERNAL_DOWNLOADS]: The skill downloads generated images from the fal.ai service to the local output directory. This is the intended primary function of the skill.
  • [PROMPT_INJECTION]: The skill accepts user-defined prompts for image generation. Although this is an injection surface, the risk is localized to the image generation process and does not affect the host system's security or the agent's core instructions.
  • [COMMAND_EXECUTION]: The skill instructions direct the AI agent to execute local Python scripts via standard methods to facilitate the generation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 04:57 PM
Security Audit — agent-trust-hub — image-portrait