image
Warn
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches a remote configuration catalog from a URL defined in the IMAGE_CATALOG_URL environment variable in catalog.py and downloads images from user-supplied URLs in client.py.
- [DYNAMIC_EXECUTION]: The skill uses a dynamic catalog system that loads model metadata, physical endpoints, and parameter validation rules from a remote JSON source at runtime. While the data is used for configuration, this mechanism allows for the dynamic alteration of the skill's network behavior.
- [INDIRECT_PROMPT_INJECTION]: The skill's inspect and edit functions ingest and process external images which can contain malicious instructions intended to influence the behavior of the agent.
- Ingestion points: image_paths and image_urls arguments in the edit, remove_background, and inspect functions.
- Boundary markers: The skill uses predefined system instructions (mode hints) but lacks specific delimiters or escaping for image-embedded content.
- Capability inventory: The skill can read local image files, write to output directories, and make POST requests to external APIs.
- Sanitization: No sanitization or safety filtering of image pixel data or metadata is performed before processing by vision models.
- [DATA_EXFILTRATION]: Local image files are read, converted to Base64 data URIs, and sent to external services (fal.run and openrouter.ai). Furthermore, the skill explicitly disables SSL certificate verification (verify=False) and suppresses insecure request warnings in client.py and image_skill.py, exposing API keys and user data to man-in-the-middle attacks.
Audit Metadata