video-stickfigure

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs shell execution by calling a Python script in SKILL.md: python ~/.openclaw/skills/image-service/scripts/text_to_image.py "[prompt]". Because user-supplied descriptions are included in the [prompt] argument without sanitization, an attacker could potentially execute arbitrary commands by injecting shell metacharacters into the description field.
  • [INDIRECT_PROMPT_INJECTION]: A vulnerability surface exists where untrusted data is processed.
  • Ingestion points: The [动作描述] (action description) placeholder in SKILL.md takes external input from the agent's task description.
  • Boundary markers: None are present; the input is directly interpolated into a shell command context within double quotes.
  • Capability inventory: The skill utilizes shell command execution and file system writing through the OpenCV library.
  • Sanitization: There is no evidence of escaping, validation, or filtering of user-supplied input before it is interpolated into the command string.
  • [DYNAMIC_EXECUTION]: The skill instructs the agent to execute Python code using shell redirection (python3 << 'EOF') in SKILL.md. This pattern of generating and running scripts at runtime is a form of dynamic execution that can be risky if the input to the script is not strictly controlled.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:24 AM
Security Audit — agent-trust-hub — video-stickfigure