reference-art-loop-codex
Warn
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill incorporates the "HERO-Anti-OverDefense" protocol, which provides explicit directives to override standard AI safety and reliability behaviors. These instructions command the agent to avoid "defensive scaffolding," "rubrics," "caveat sprinkling," and "corner-case obsession," effectively instructing the model to bypass platform-level guardrails designed to ensure safe and predictable behavior.
- [DYNAMIC_EXECUTION]: The skill generates p5.js source code at runtime and executes it within a headless browser context to perform local rendering and capture screenshots. This involves the creation and execution of dynamic, agent-generated scripts within the user's environment.
- [COMMAND_EXECUTION]: The instructions direct the agent to execute shell commands, including launching headless browsers (Edge/Chrome) with specific flags (e.g.,
--headless=new,--disable-gpu), starting local HTTP servers using Python, and orchestrating subagents using platform-specific tools (collaboration.spawn_agent). - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its visual iteration loop.
- Ingestion points: The agent ingests untrusted "style source" images and user-provided subject descriptions.
- Boundary markers: Prompts use delimiters (e.g.,
=== SCOPE LIMITS ===) to separate instructions, but these do not prevent adversarial content in visual inputs from influencing the vision-capable subagent. - Capability inventory: The skill has capabilities to execute shell commands, write files, and spawn subagents.
- Sanitization: There is no evidence of sanitization or content filtering for the visual or text inputs processed during the review loop.
- [EXTERNAL_DOWNLOADS]: The skill references the use of external CJK web fonts and assets. While the execution playbook recommends localizing these, the fallback mechanisms and initial setup involve fetching content from external network sources.
Audit Metadata