image-forge

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: All scripts in the skill (batch_ops.py, image_info.py, image_pipeline.py, montage_builder.py, smart_crop.py) utilize subprocess.run to call the magick CLI. These calls are implemented using list-based arguments rather than shell strings, which is a key security measure against shell injection. The scripts also use shlex.join to safely format commands for display during dry-runs.
  • [EXTERNAL_DOWNLOADS]: The skill relies on external libraries like transparent-background and rembg. The SKILL.md file correctly notes that transparent-background downloads a model file (~170MB) upon first use. This is standard behavior for the library and is presented transparently to the user.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes images and JSON specifications which could be controlled by an external actor, it does not interpret the content of these files as executable code. The declarative JSON format in image_pipeline.py ensures that the agent's actions are mapped to specific, pre-defined ImageMagick operations, providing a layer of abstraction and safety.
  • [DYNAMIC_EXECUTION]: The image_pipeline.py script dynamically constructs a single, chained ImageMagick command from a JSON specification. This complex command building is handled through explicit mapping of JSON keys to command-line flags, avoiding the dangers of raw string concatenation for shell execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:07 AM
Security Audit — agent-trust-hub — image-forge