gemini-watermark-remove
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOW
Full Analysis
- [DATA_EXFILTRATION] (SAFE): The script
scripts/remove-watermark.jsdoes not use any network modules or external transmission commands. All processing is localized to reading from and writing to the user-specified filesystem paths. - [REMOTE_CODE_EXECUTION] (SAFE): No instances of
eval(),exec(), orFunction()constructors were found. The script does not download and execute remote scripts or piped commands. - [EXTERNAL_DOWNLOADS] (INFO): The skill lists
sharpas a dependency. Sharp is a standard, reputable, and whitelisted library for image processing on the NPM registry. [TRUST-SCOPE-RULE] applies to the registry source. - [PROMPT_INJECTION] (SAFE): The README and SKILL metadata contain legitimate usage instructions and technical descriptions. There are no attempts to override agent instructions or bypass safety filters.
- [INDIRECT_PROMPT_INJECTION] (INFO): The skill processes external image data but has no natural language processing capabilities that could be subverted by embedded instructions. It operates as a deterministic transformation tool (Capability Tier: INFO).
Audit Metadata