video-stickfigure
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs shell execution by calling a Python script in
SKILL.md:python ~/.openclaw/skills/image-service/scripts/text_to_image.py "[prompt]". Because user-supplied descriptions are included in the[prompt]argument without sanitization, an attacker could potentially execute arbitrary commands by injecting shell metacharacters into the description field. - [INDIRECT_PROMPT_INJECTION]: A vulnerability surface exists where untrusted data is processed.
- Ingestion points: The
[动作描述](action description) placeholder inSKILL.mdtakes external input from the agent's task description. - Boundary markers: None are present; the input is directly interpolated into a shell command context within double quotes.
- Capability inventory: The skill utilizes shell command execution and file system writing through the OpenCV library.
- Sanitization: There is no evidence of escaping, validation, or filtering of user-supplied input before it is interpolated into the command string.
- [DYNAMIC_EXECUTION]: The skill instructs the agent to execute Python code using shell redirection (
python3 << 'EOF') inSKILL.md. This pattern of generating and running scripts at runtime is a form of dynamic execution that can be risky if the input to the script is not strictly controlled.
Audit Metadata