etsy-tony-full-photo-15

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data (product descriptions and images) to build image generation prompts. Ingestion happens at the 'Product-Truth Gate' (SKILL.md). While the prompt is wrapped in a mandatory template, there is no specific sanitization to prevent user data from hijacking the prompt generation process. Capabilities include image generation and writing to the './etsy-output' directory.
  • [DYNAMIC_EXECUTION]: The skill generates deterministic graphics, such as measurement overlays and variation labels, using the Pillow library or SVG/HTML formats (references/image-rule-details.md). This runtime creation of visual assets from templates is a low-risk dynamic behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:46 AM
Security Audit — agent-trust-hub — etsy-tony-full-photo-15