taste-image-to-code

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains structural directives and quality-focused instructions for the AI agent. There are no attempts to bypass safety filters, ignore system prompts, or override agent constraints.
  • [DATA_EXFILTRATION]: No patterns for sensitive file access or unauthorized network data exfiltration were found. The skill describes a local visual-to-code translation workflow.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns, script downloads, or package installations were detected. The skill consists entirely of markdown instructions and metadata.
  • [OBFUSCATION]: No obfuscated content, encoded strings, zero-width characters, or hidden acrostics were identified in any of the skill files.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes user design requests, it does not contain instructions that would make it vulnerable to specific injection attacks beyond standard conversational AI operation. The workflow emphasizes manual analysis of generated visuals.
  • [PRIVILEGE_ESCALATION]: No commands related to privilege escalation, such as sudo or system policy modifications, are present.
  • [PERSISTENCE]: No mechanisms for establishing persistence, such as modifying startup scripts or cron jobs, were found.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill does not use dynamic shell execution syntax within its markdown files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 07:10 AM
Security Audit — agent-trust-hub — taste-image-to-code