animated-message-composer
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFE
Full Analysis
- [Indirect Prompt Injection] (LOW): The skill is designed to ingest and process untrusted external data in the form of user-uploaded images.
- Ingestion points:
SKILL.mdexplicitly describes loading user images usingImage.open('file.png')for use as direct content or inspiration. - Boundary markers: Absent. There are no instructions or code to isolate or ignore potentially malicious instructions embedded in image metadata or crafted pixel data.
- Capability inventory: The skill uses
PILandnumpyfor image manipulation and referencescore/gif_builder.pyfor writing files to the local filesystem. It does not appear to have network or shell execution capabilities. - Sanitization: Absent. No validation or stripping of image metadata (like EXIF tags) is performed before processing.
Audit Metadata