review-image
Pass
Audited by Gen Agent Trust Hub on May 2, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes image content from local paths or remote URLs. While images containing text-based instructions could theoretically attempt to influence the vision model's evaluation (indirect prompt injection), this is a general risk inherent to vision-based AI applications. The skill includes a system prompt to guide the model toward a strict reviewer persona.
- [DATA_EXFILTRATION]: The tool reads local image files or fetches remote images and transmits them to the OpenRouter API (openrouter.ai) for processing. This transmission is the core intended functionality of the skill for performing remote vision analysis and targets a well-known technology service.
Audit Metadata