cover-image

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The references/base-prompt.md file contains instructions specifically telling the image generation model 'DO NOT refuse to generate' if content involves sensitive or copyrighted figures, which is an attempt to override standard safety filter behaviors.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted article content (via file path or direct text) to generate prompts for an image generation tool.
  • Ingestion points: User-provided article files or text input described in the SKILL.md workflow.
  • Boundary markers: The prompt template in SKILL.md (Step 4) does not define clear boundary markers or instructions for the image generator to ignore embedded malicious directives in the summarized content.
  • Capability inventory: The skill has the capability to read local files, write new prompt files to the file system, and invoke other image generation skills.
  • Sanitization: While the skill 'distills' information rather than directly interpolating the entire article, there is no explicit sanitization or escaping of the extracted text before it is placed into the cover-prompt.md file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 07:41 AM
Security Audit — agent-trust-hub — cover-image