NYC

creative-generation-agent

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS] (LOW): The ImageGenerationAgent class in examples/image_generation.py utilizes StableDiffusionPipeline.from_pretrained to download model weights from runwayml/stable-diffusion-v1-5 on Hugging Face. While Hugging Face is a trusted organization, the download of external model weights constitutes an external dependency.
  • [PROMPT_INJECTION] (LOW): The skill exhibits a surface for indirect prompt injection.
  • Ingestion points: User-provided topic in examples/podcast_producer.py and prompt in examples/image_generation.py.
  • Boundary markers: Absent; user input is directly interpolated into multi-line instructional templates.
  • Capability inventory: Generation of image and audio files.
  • Sanitization: No input validation or escaping is applied to user-controlled data before it is included in model prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:21 PM