ai-provider-claude-vision

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides legitimate integration patterns for the Anthropic Claude Vision API. It correctly handles media content blocks and documents platform-specific safety policies, such as the refusal to identify specific individuals.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of external images and documents, which serves as an ingestion surface for potential indirect prompt injection. Ingestion points: local file reading in examples/core.md and examples/extraction.md. Boundary markers: No explicit delimiters for binary image/document blocks. Capability inventory: multimodal analysis through @anthropic-ai/sdk. Sanitization: Documentation references safety policies regarding person identification and clinical imaging limitations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 03:56 PM
Security Audit — agent-trust-hub — ai-provider-claude-vision