The skill introduces supply chain risks by loading
Claims to do
When to Use: Use when the main artifact is an image file or visual asset, especially when format choice, resizing, cropping, compression, metadata, transparency, color profile, responsive delivery, social specs, marketplace requirements, or print readiness matter.
Actually does
This skill functions as a comprehensive guide for image processing, offering best practices and workflows for various image types and destinations. It provides advice on format choice, resizing, compression, metadata handling, and color profiles, referencing tools like ImageMagick and Pillow for concrete examples. The skill itself does not execute commands or contact external URLs for image manipulation, but rather provides structured advice for users.
openclaw skills install ivangdavila/imageThe skill instructs the agent to load external Markdown files (e.g., `web.md`, `social.md`) for specialized context. This introduces a supply chain risk, as malicious content in these external files could poison the agent's RAG context or influence its reasoning.
If the task is destination-specific, load the matching file before deciding: / `web.md` for responsive delivery...
The skill suggests installing related skills using `clawhub install <slug>`, which, despite requiring user confirmation, represents a supply chain risk. A malicious skill installed via this mechanism could extend an attacker's control over the agent.
Install with `clawhub install <slug>` if user confirms:
The stated purpose implies the skill will 'create, inspect, process, and optimize' image files. However, the skill's content is purely instructional and advisory, providing guidance on *how* to perform these actions rather than executing them directly.
The skill content consists entirely of text-based advice, workflows, and references to external tools/files (e.g., 'commands.md' for 'concrete ImageMagick or Pillow examples'). There are no executable commands or API calls within the skill to perform image manipulation.
The instruction to install related skills explicitly requires user confirmation. While a security measure, frequent prompts for installation or other actions could lead to human approval fatigue, potentially allowing a malicious skill to be installed without proper scrutiny.
Install with `clawhub install <slug>` if user confirms:
[](https://mondoo.com/ai-agent-security/skills/clawhub/ivangdavila/image)<a href="https://mondoo.com/ai-agent-security/skills/clawhub/ivangdavila/image"><img src="https://mondoo.com/ai-agent-security/api/badge/clawhub/ivangdavila/image.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/clawhub/ivangdavila/image.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.