novelai-cli
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the
novelai-image-mcppackage from PyPI usingpip installor execute it viauvx. This package is a vendor-owned resource associated with the author 'xinvxueyuan'. - [COMMAND_EXECUTION]: Provides instructions for driving the
novelai-image-mcpCLI tool to interact with the NovelAI API for tasks such as image generation, upscaling, and transformation. - [INDIRECT_PROMPT_INJECTION]: The skill exposes an attack surface where user-supplied prompts are interpolated into shell commands. 1. Ingestion points: The
--promptand--negativeflags for thegenerate,colorize, andemotionsubcommands. 2. Boundary markers: Absent. 3. Capability inventory: Shell execution of thenovelai-image-mcpCLI. 4. Sanitization: Absent in the provided instructions.
Audit Metadata