etsy-tony-full-photo-engine

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-supplied reference images and product descriptions to generate shot briefs. While this creates a data ingestion surface, the skill includes instructions to strictly separate product identity from reference scenes and uses structured audit fields (e.g., reference_invariants) to maintain control over the generated content.
  • [DYNAMIC_EXECUTION]: For the 'Dimension Infographic Workflow,' the instructions suggest using deterministic graphics methods like Pillow or HTML/CSS rendering. This may result in the agent generating and running localized scripts to create precise measurement overlays, which is a functional requirement for the e-commerce use case.
  • [SAFE]: The skill includes security-positive routing rules that explicitly prohibit calling external planning or image APIs (e.g., OpenRouter, kuai.host). It also prevents the agent from requesting or reading external API keys, ensuring that all data processing remains within the trusted environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:47 AM
Security Audit — agent-trust-hub — etsy-tony-full-photo-engine