skills/styleof/superpowers/p-image/Gen Agent Trust Hub

p-image

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references installation instructions and documentation from the inference.sh official domains and GitHub repositories (github.com/inference-sh/*, inference.sh). It suggests installing the belt-sh/cli tool using npx, which is standard for this ecosystem.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface for indirect prompt injection via the processing of external images.
  • Ingestion points: The images input parameter in the pruna/p-image-edit and pruna/p-image-edit-lora models allows processing of remote URLs.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded content are present in the provided examples.
  • Capability inventory: The skill uses the Bash tool to execute belt CLI commands.
  • Sanitization: The skill instructions do not include validation or sanitization steps for the content of the external image URLs provided at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:21 PM
Security Audit — agent-trust-hub — p-image