visual-ralph
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied input via the
{{ARGUMENTS}}placeholder, which drives a workflow involving shell command execution and file system modifications without strict boundary markers or sanitization. - Ingestion points: The
{{ARGUMENTS}}placeholder at the end ofSKILL.mdis the primary entry point for untrusted data. - Boundary markers: Absent. The skill does not define specific delimiters or instructions for the agent to ignore potentially malicious embedded commands within the user input.
- Capability inventory: The skill is authorized to execute shell commands for image generation (
omx imagegen), screenshotting, and repository-specific verification/linting. It also involves writing files to.omx/artifacts/and modifying repo-native code through$ultragoal. - Sanitization: Absent. There is no mention of validation or escaping for the data interpolated into the agent's context.
Audit Metadata