thirds-image-packs
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads generated image archives from a dynamic
archive_urland references documentation and configuration files from vendor-controlled domains including thirds.ai and github.com/thirdsai. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect instructions through external data ingestion.
- Ingestion points: The agent is instructed to download an archive and inspect its
manifest.jsonfile to report status and dimensions (SKILL.md, Step 4). - Boundary markers: There are no instructions provided to treat the manifest content as untrusted or to ignore embedded natural language instructions.
- Capability inventory: The skill uses tools to adapt templates, create image packs, and poll status, and performs authenticated REST API calls to vendor endpoints.
- Sanitization: No validation or sanitization logic is specified for the contents of the downloaded manifest.
- [COMMAND_EXECUTION]: The skill instructs the agent to utilize specific Model Context Protocol (MCP) tools (
get_template_version,adapt_template,create_image_pack, etc.) and authenticated REST API routes to manage design adaptation and image generation workflows.
Audit Metadata