lyt-page-diagnosis

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided content, including product images, screenshots, and business data descriptions. This ingestion of external data creates a potential surface for indirect prompt injection attacks.
  • Ingestion points: The skill accepts single or multiple product images, screenshots of detail pages/back-end data, and textual descriptions of products and markets (SKILL.md).
  • Boundary markers: The skill lacks explicit prompt delimiters or technical markers to isolate user-provided data. It relies on a logical 'image forensics' process to distinguish visible facts from assumptions (references/page-diagnosis-core.md).
  • Capability inventory: The agent has the capability to read multiple local reference files and is instructed to call image generation or editing tools to implement design changes (SKILL.md, references/revision-brief.md).
  • Sanitization: There is no evidence of OCR filtering or sanitization of text extracted from user-provided images before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 12:24 PM
Security Audit — agent-trust-hub — lyt-page-diagnosis