image-generate

Pass

Audited by Gen Agent Trust Hub on Feb 19, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [General] (SAFE): The provided files consist solely of documentation and metadata. No scripts, binaries, or configuration files containing executable code were present for analysis.
  • [Credentials] (SAFE): No hardcoded API keys or secrets were detected. The documentation correctly specifies that required API keys (FAL_API_KEY, REPLICATE_API_TOKEN, etc.) must be provided via environment variables.
  • [Indirect Prompt Injection] (LOW): The skill is designed to process text prompts for image generation, which serves as a potential surface for indirect prompt injection if the agent populates this field with untrusted data. 1. Ingestion points: The --prompt command-line argument. 2. Boundary markers: Not specified in documentation. 3. Capability inventory: Generates images via external providers. 4. Sanitization: Not specified in documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 19, 2026, 01:20 AM