etsy-tony-scene-photo-3

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided text descriptions and product images to generate image prompts, which represents an attack surface for indirect prompt injection. 1. Ingestion points: User-provided product reference photos and text descriptions (as seen in SKILL.md). 2. Boundary markers: There are no explicit delimiters or instructions provided to separate user-provided content from the system prompt during interpolation. 3. Capability inventory: The skill has the ability to call image generation tools and write files to the local directory 'etsy-output/scene-photo-3'. 4. Sanitization: The skill instructions focus on visual verification but do not mention sanitizing or filtering user input before use in tool prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:20 AM
Security Audit — agent-trust-hub — etsy-tony-scene-photo-3