gemini-watermark-remove

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOW
Full Analysis
  • [DATA_EXFILTRATION] (SAFE): The script scripts/remove-watermark.js does not use any network modules or external transmission commands. All processing is localized to reading from and writing to the user-specified filesystem paths.
  • [REMOTE_CODE_EXECUTION] (SAFE): No instances of eval(), exec(), or Function() constructors were found. The script does not download and execute remote scripts or piped commands.
  • [EXTERNAL_DOWNLOADS] (INFO): The skill lists sharp as a dependency. Sharp is a standard, reputable, and whitelisted library for image processing on the NPM registry. [TRUST-SCOPE-RULE] applies to the registry source.
  • [PROMPT_INJECTION] (SAFE): The README and SKILL metadata contain legitimate usage instructions and technical descriptions. There are no attempts to override agent instructions or bypass safety filters.
  • [INDIRECT_PROMPT_INJECTION] (INFO): The skill processes external image data but has no natural language processing capabilities that could be subverted by embedded instructions. It operates as a deterministic transformation tool (Capability Tier: INFO).
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 01:59 AM