visual-ralph

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied input via the {{ARGUMENTS}} placeholder, which drives a workflow involving shell command execution and file system modifications without strict boundary markers or sanitization.
  • Ingestion points: The {{ARGUMENTS}} placeholder at the end of SKILL.md is the primary entry point for untrusted data.
  • Boundary markers: Absent. The skill does not define specific delimiters or instructions for the agent to ignore potentially malicious embedded commands within the user input.
  • Capability inventory: The skill is authorized to execute shell commands for image generation (omx imagegen), screenshotting, and repository-specific verification/linting. It also involves writing files to .omx/artifacts/ and modifying repo-native code through $ultragoal.
  • Sanitization: Absent. There is no mention of validation or escaping for the data interpolated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:53 PM
Security Audit — agent-trust-hub — visual-ralph