minimax-understand-image

Fail

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install the 'uv' package manager using a shell pipe from 'https://astral.sh/uv/install.sh'. While piped execution is a sensitive pattern, 'astral.sh' is the official domain for the well-known and widely used 'uv' development tool, and the download is intended for environment setup.
  • [COMMAND_EXECUTION]: The Python script 'scripts/understand_image.py' utilizes 'subprocess.Popen' to execute the 'uvx' command-line tool. This execution is necessary for the skill's primary function of communicating with the MiniMax MCP server via standard input/output.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a bridge for processing untrusted external data.
  • Ingestion points: External image paths/URLs and natural language prompts are accepted via command-line arguments in 'scripts/understand_image.py'.
  • Boundary markers: The script does not implement explicit boundary markers or instructions for the model to ignore embedded data instructions when processing the prompt.
  • Capability inventory: The skill can perform local file system writes (configuring API keys) and execute subprocesses ('uvx').
  • Sanitization: Arguments are passed to the MCP server via JSON-RPC, providing basic structural sanitization, but natural language content remains unfiltered.
Recommendations
  • HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 16, 2026, 04:35 AM
Security Audit — agent-trust-hub — minimax-understand-image