NYC

multimodal-looker

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [Prompt Injection] (SAFE): No instructions were found that attempt to bypass AI safety filters, ignore previous instructions, or override system-level constraints.
  • [Data Exposure & Exfiltration] (SAFE): The skill does not contain any hardcoded credentials, sensitive file paths, or network operations that could exfiltrate data. It focuses entirely on analyzing user-provided visual content.
  • [Remote Code Execution] (SAFE): There are no scripts, package installations, or command-line executions involved in this skill.
  • [Indirect Prompt Injection] (LOW): Because the skill is designed to process external content (images, PDFs, charts), it is theoretically susceptible to indirect prompt injection if an attacker embeds malicious text within those visual files. However, since the skill lacks dangerous capabilities like file writing or network requests, the risk is minimal and restricted to generating deceptive text output.
  • [Obfuscation] (SAFE): The skill is written in clear, human-readable Markdown and Chinese/English text with no hidden characters or encoded strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:07 PM