paper-illustration-image2
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a Python helper script (
scripts/paper_illustration_image2.py) to interface with the local environment. This script usessubprocess.runto execute a localcodexbinary for a status check. The call is restricted to a 'ping' command with a fixed set of arguments and does not involve a shell, which mitigates the risk of command injection. - [INDIRECT_PROMPT_INJECTION]: The workflow involves processing user-provided descriptions to plan and review illustrations. While this introduces an indirect prompt injection surface, the skill incorporates a multi-stage review process (planner, layout optimization, style verification, and visual review) with specific scoring criteria (1-10) to ensure logical consistency and adherence to academic standards before finalizing output.
- [SAFE]: The skill's file system operations are localized to the user's project workspace and a dedicated
figures/ai_generated/output directory. The path resolution logic for the helper script uses a tiered approach to safely locate the file within the skill's distribution or the local environment.
Audit Metadata