visual-asset-studio

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to run local Python scripts (generate_image.py and screenshot.py) to generate images and capture web content. This is a core part of its intended functionality.
  • [EXTERNAL_DOWNLOADS]: One of the tools referenced by this skill (the screenshot tool) contains a feature to upload images to external services. While intended for sharing assets in developer workflows, users should monitor network activity during these operations.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) because it passes user-supplied prompts directly to underlying image and design generation tools.
  • Ingestion points: The skill accepts user requests for mockups, posters, and illustrations which are then used to instruct sub-skills (SKILL.md).
  • Boundary markers: The instructions do not define clear delimiters or warnings to ignore malicious instructions embedded in the user's design requests.
  • Capability inventory: Through its sub-skills, the agent can execute shell commands, generate files, and perform network uploads (references/component-skills.md).
  • Sanitization: There is no evidence of input validation or sanitization to prevent adversarial instructions from influencing the behavior of the sub-skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 08:26 PM
Security Audit — agent-trust-hub — visual-asset-studio