etsy-tony-photo-review
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of instructional prompts and configuration metadata. No evidence of prompt injection, data exfiltration, or malicious persistence was detected.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied images (ingestion point). However, it does not request tool permissions (allowed-tools is absent) or include scripts with network/file-system capabilities, eliminating the risk of data exfiltration or system modification via data-embedded instructions. The skill includes specific boundary logic (distinguishing filenames from actual images) to maintain context integrity.
Audit Metadata