Skip to content
Report library
Purpose / Development

Image To Code Skill Security Audit

What the author says it does (original text)

Elite website image-to-code skill for Codex. For visually important web tasks, it must first generate the design image(s) itself, deeply analyze them, then implement the website to match them as closely as possible. In Codex, it must prefer large, readable, section-specific images instead of tiny compressed boards, generate fresh standalone images for sections or detail views instead of cropping o

Independent security check

Security risks found

Files checked
1
Risks found
2
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.No risks found
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.Risks found: 2
Medium risk

Mandatory multi-image generation without a clear budget cap may cause unexpected charges

Source references: 5
What we found

The Skill requires image generation first, explicitly prefers too many images over too few, and permits second or third generations for the same section. An 8–12-section page could therefore trigger many billed generations and retries.

Why this matters

With a per-use or quota-based image service, the user could consume substantial paid credits, quota, and time before frontend implementation begins.

The source supports this risk. Visual website tasks mandate image generation first and prefer one image per section; complex or unclear sections may require extra images or regeneration. If the image service charges per request or usage, an 8–12-section site plus retries could create unexpected costs. No total-image, retry, or budget cap is stated. Users can ask for a pre-generation count/cost estimate, hard limits, and confirmation before exceeding them.

SKILL.md:114In the instructionsOpen original file
For website design requests where visual quality matters, image generation is mandatory first.This means:1. generate the design image or image set yourself first2. deeply inspect and analyze the generated image(s)3. extract the design system from them4. implement the frontend only after that
Show 4 other places
SKILL.md:153In the instructionsOpen original file
Strong rule:- it is better to generate too many clear images than too few compressed images- it is better to generate one clear image per section than one unreadable board for the whole site- it is better to create an extra detail image than to guess details laterNever reduce image count just for convenience if that harms quality.
SKILL.md:169In the instructionsOpen original file
Default rule inside Codex:- 1 section requested → generate 1 image- 2 sections requested → generate 2 images- 3 sections requested → generate 3 images- 4 sections requested → generate 4 images- 5 sections requested → generate 5 images- 6 sections requested → generate 6 images- 7 sections requested → generate 7 images- 8 sections requested → generate 8 images- 9 sections requested → generate 9 images- 10 sections requested → generate 10 images- and so on when reasonable
SKILL.md:285In the instructionsOpen original file
Do not hesitate to create a second or third extraction-oriented image for a section if the first image is too broad.
SKILL.md:646In the instructionsOpen original file
If the user asks for:- a hero only → generate 1 hero image- 4 sections → generate 4 section images- 8 sections → generate 8 section images- 12 sections → generate 12 section images when reasonableGeneral preference:- one section = one primary image- one complex section = one primary image + one or more optional detail images- one unclear section = regenerate it again as a fresh clean standalone image
Medium risk

Generated prices, testimonial identities, and marketing claims may be published as facts

Source references: 4
What we found

The model creates the reference images itself, but the Skill then directs it to extract pricing labels, feature names, testimonial names and roles, use readable text, and faithfully copy the references. It does not require validation against user-supplied business facts.

Why this matters

Invented prices, endorsements, roles, or product promises from an image could reach a real website, misleading visitors and creating reputational, consumer-protection, or false-advertising risk.

The source supports this risk, conditional on generated images containing invented but readable business copy. The Skill creates its own references, then directs extraction and use of pricing, features, and testimonial names/roles while requiring faithful implementation. It does not require verification against user-supplied business records. Fictional prices, endorsements, or capabilities could therefore be published as facts, affecting visitor decisions and creating reputational or compliance risk. Users can require placeholders and item-by-item approval before publication.

SKILL.md:55In the instructionsOpen original file
IMPORTANT:For visual website tasks, you must first generate the design image(s) yourself.Then you must deeply analyze the generated image(s).Only after that should you implement the frontend.Do not skip image generation when image generation is available.Do not begin with freeform coding first.The generated image(s) are the primary visual source of truth.
Show 3 other places
SKILL.md:723In the instructionsOpen original file
When text is readable in the generated section image, extract it and use it.Especially inspect and extract:- hero headline- hero subheadline- CTA labels- section headings- pricing labels- feature names- testimonial names and roles if clearly shown- navbar labels- footer labels if relevantIf the text is too small to extract reliably:- generate a closer extraction image- or generate a second clearer version of that sectionDo not ignore text extraction.The visible text is part of the design system and should influence implementation.
SKILL.md:837In the instructionsOpen original file
After generating and analyzing the reference image(s), implement the website in a copy-oriented way.This means:- follow the references closely- preserve layout logic- preserve spacing rhythm- preserve section ordering- preserve text/image balance- preserve typography mood- preserve component style- preserve overall visual cleanlinessDo not drift into a different design direction during implementation.Do not “improve” the design by replacing it with a generic coded layout.The goal is not:- inspired by the imageThe goal is:- visually faithful to the image, translated into real frontend
SKILL.md:114In the instructionsOpen original file
For website design requests where visual quality matters, image generation is mandatory first.This means:1. generate the design image or image set yourself first2. deeply inspect and analyze the generated image(s)3. extract the design system from them4. implement the frontend only after that

Inside this skill

8 instruction sections

For visual website tasks, the Skill mandates a fixed sequence: generate reference images, analyze them, and then implement the frontend, treating the generated images as the primary design source.

View source
SKILL.md:55In the instructionsOpen original file
IMPORTANT:For visual website tasks, you must first generate the design image(s) yourself.Then you must deeply analyze the generated image(s).Only after that should you implement the frontend.Do not skip image generation when image generation is available.Do not begin with freeform coding first.The generated image(s) are the primary visual source of truth.

In Codex, the Skill defaults to a separate large image for each page section and calls for additional or regenerated images when details remain unclear.

View source
SKILL.md:168In the instructionsOpen original file
Default rule inside Codex:- 1 section requested → generate 1 image- 2 sections requested → generate 2 images- 3 sections requested → generate 3 images- 4 sections requested → generate 4 images- 5 sections requested → generate 5 images- 6 sections requested → generate 6 images- 7 sections requested → generate 7 images- 8 sections requested → generate 8 images- 9 sections requested → generate 9 images- 10 sections requested → generate 10 images- and so on when reasonable
SKILL.md:261In the instructionsOpen original file
If a section image still does not expose the necessary detail clearly enough, generate an additional detail image for that same section.Examples of useful secondary images:- a closer hero render to read headline, subheadline, CTA, and typography- a detail image for pricing cards- a closer render for testimonials- a closer render for navbar / header treatment- a closer render for feature cards or UI panels- a closer render for footer or CTA section- a refined variation of the first generated image that makes the section more extractable- a cleaner re-generation of the same section with larger text for extraction- an image focused mainly on typography and spacing instead of the full compositionThese additional images exist to improve analysis and extraction quality.Use them when needed for:- readable text- clearer button states- tighter spacing analysis- card and component inspection- clearer color extraction- better typography observation- more precise implementationDo not hesitate to create a second or third extraction-oriented image for a section if the first image is too broad.
Start here · InstructionsSKILL.md
image-to-code
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source. 30 more sections are available in the original file.
Files and check records1 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
Lines read
1,229
File checksum (to compare versions)
a72df672701f11e780a83210459d8fa6db56b6583efa0854a099e786ff49f843