cover-image
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The
references/base-prompt.mdfile contains instructions specifically telling the image generation model 'DO NOT refuse to generate' if content involves sensitive or copyrighted figures, which is an attempt to override standard safety filter behaviors. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted article content (via file path or direct text) to generate prompts for an image generation tool.
- Ingestion points: User-provided article files or text input described in the
SKILL.mdworkflow. - Boundary markers: The prompt template in
SKILL.md(Step 4) does not define clear boundary markers or instructions for the image generator to ignore embedded malicious directives in the summarized content. - Capability inventory: The skill has the capability to read local files, write new prompt files to the file system, and invoke other image generation skills.
- Sanitization: While the skill 'distills' information rather than directly interpolating the entire article, there is no explicit sanitization or escaping of the extracted text before it is placed into the
cover-prompt.mdfile.
Audit Metadata