gemini-image
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [External Downloads] (LOW): The skill requires the installation of the
google-generativeaipackage. This is a trusted dependency maintained by thegoogleorganization, which is a trusted source. Evidence:pip install google-generativeaiin SKILL.md. - [Command Execution] (LOW): The skill suggests using the macOS
screencaptureutility to generate input files. This is a standard system utility used for the skill's primary function. Evidence:screencapture -i /tmp/bug.pngin SKILL.md. - [Indirect Prompt Injection] (LOW): The skill is susceptible to visual prompt injection, where malicious instructions hidden within processed images (OCR or visual reasoning) could attempt to override the agent's behavior.
- Ingestion points: Local image files (PNG, JPEG, etc.) passed to the
-fflag in the CLI examples. - Boundary markers: Not present in the provided prompt templates.
- Capability inventory: The model processes visual input to generate text descriptions, React components, and bug reports.
- Sanitization: No input sanitization or validation of image content is performed; the skill relies on the model's internal safety guardrails.
Audit Metadata