ornament-style-modern
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill constructs prompts for an image generation tool by directly interpolating user-defined inputs, such as genre and motifs, which creates an indirect prompt injection surface.
- Ingestion points: User-defined parameters specified in the Inputs section of SKILL.md.
- Boundary markers: Absent; user inputs are placed into the template in Step 4 without delimiters or instructions to ignore embedded commands.
- Capability inventory: Image generation using the mcp__hf-mcp-server__gr1_z_image_turbo_generate tool as described in Step 6.
- Sanitization: Absent; the procedure does not include steps for escaping or validating user-provided strings.
- [EXTERNAL_DOWNLOADS]: The skill uses WebSearch and WebFetch for design research and hf-mcp-server for image generation; both are classified as well-known technology services and are documented neutrally.
Audit Metadata