NYC

collage-layout-expert

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE] (SAFE): No malicious behaviors, such as data exfiltration, prompt injection, or code obfuscation, were detected in any of the skill's components.
  • [EXTERNAL_DOWNLOADS] (LOW): The skill utilizes Firecrawl and WebFetch for research and Stability AI for content generation. These interactions are legitimate for a design skill and occur within defined tool parameters.
  • [COMMAND_EXECUTION] (LOW): The skill specifies Bash as an allowed tool in its frontmatter. However, the provided reference implementations are confined to standard image processing logic using Python libraries like OpenCV and NumPy.
  • [INDIRECT PROMPT INJECTION] (LOW): The use of web-fetching tools creates an ingestion surface for untrusted external data. (Ingestion points: Firecrawl and WebFetch tools in SKILL.md; Boundary markers: None specified in the reference snippets; Capability inventory: Bash, Write, and image generation tools; Sanitization: Basic validation of image coordinates and parameters exists in utility functions).
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:03 PM