product-photography

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOWPROMPT_INJECTIONNO_CODE
Full Analysis
  • Indirect Prompt Injection (LOW): The skill identifies a surface for indirect prompt injection through its use of un-sanitized placeholders in prompt templates.
  • Ingestion points: Untrusted data enters the agent context through placeholders such as [Product name], [Product], [setting], and [mood] found throughout SKILL.md.
  • Boundary markers: There are no delimiters or 'ignore' instructions wrapping the interpolated variables.
  • Capability inventory: The skill leverages image generation capabilities (via integration with FAL.ai/Image Generation skills).
  • Sanitization: No escaping or validation of external content is specified.
  • No Code (SAFE): The skill is entirely documentation-based and contains no scripts, binaries, or automated command execution logic.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 01:11 AM