image-service

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill uses internal subprocess calls to modularize functionality, executing local scripts using defined paths and the current Python interpreter. This implementation avoids shell execution and command injection risks.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided Markdown files and incorporates their content into prompts sent to image generation APIs.
  • Ingestion points: Markdown files (articles, stories) are read and parsed in scenario scripts such as scenes/article-illust/zlab_article_illustrator.py, scenes/comic/zlab_comic.py, and scenes/slide-deck/zlab_slide_deck.py.
  • Boundary markers: The skill does not implement specific boundary markers or instructions to the image model to ignore instructions embedded within the user text.
  • Capability inventory: The skill performs network operations via API calls to well-known services (like OpenAI) to generate images and write those image files to the local file system.
  • Sanitization: User-provided text is interpolated directly into the image generation prompt without filtering or sanitization.
  • Context: While this represents an attack surface for indirect prompt injection, the risk is limited to the visual content of the generated images and is inherent to the tool's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:24 AM
Security Audit — agent-trust-hub — image-service