paper-illustration-image2
Pass
Audited by Gen Agent Trust Hub on Apr 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to run a local Python script (tools/paper_illustration_image2.py) for project-specific operations such as preflight checks, finalizing image artifacts, and verifying the generated output. This helper script is a core part of the skill's infrastructure.- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted data from user requests and academic text sections (ingestion points) to drive the planning and generation of figures. There are no explicit boundary markers (present/absent: absent) or sanitization procedures (present/absent: absent) described to protect the prompts from adversarial input. The capability inventory includesBashscript execution, file modification (Write,Edit), and external image generation tool calls. Visual review and scoring by the agent are used as quality controls.
Audit Metadata