immich-photo-manager
Pass
Audited by Gen Agent Trust Hub on Apr 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references and provides installation instructions for an external repository (https://github.com/drolosoft/immich-photo-manager) that is not identified as a trusted source or part of the primary vendor's infrastructure.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting and processing data from self-hosted photo libraries. 1. Ingestion points: Photo EXIF metadata, visual search results via CLIP, and library health audit reports. 2. Boundary markers: No delimiters or instruction-ignore warnings are specified in the provided documentation. 3. Capability inventory: Includes access to 21 MCP tools and 11 specialized skills for photo management and gallery generation. 4. Sanitization: No validation or sanitization procedures for ingested metadata are mentioned.
Audit Metadata