image-well
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill performs search queries across numerous well-known image services and museum databases and downloads assets from their official URLs.\n- [COMMAND_EXECUTION]: Uses the system
opencommand on macOS to allow users to view a locally generated gallery of results in their web browser.\n- [DATA_EXFILTRATION]: Accesses the local configuration file~/.config/env/secrets.envto retrieve API keys for various search services.\n- [PROMPT_INJECTION]: Ingests and displays metadata such as titles and tags from external APIs, implementing HTML escaping and filename sanitization to mitigate indirect injection risks.
Audit Metadata