Skills higgsfield-marketplace-cards
📦

higgsfield-marketplace-cards

v0.12.0 Content revision r2 Critical ⚙️ External commands🌐 Network access

Create Marketplace Product Image Sets

Marketplace listings need consistent images across main, secondary, and A+ placements. This skill routes product context to Higgsfield and returns labeled result links.

Supports: Claude Codex Code(CC)
⚠️ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "higgsfield-marketplace-cards" from https://skillstore.io/skills/higgsfield-ai-higgsfield-marketplace-cards.md and its manifest at https://skillstore.io/api/skills/higgsfield-ai-higgsfield-marketplace-cards/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.

Your Agent should still show its plan and request any confirmation required by the security policy.

Test it

Using "higgsfield-marketplace-cards". Create a main image for a sparkling peach lemonade can.

Expected outcome:

Marketplace cards ready: Main image link.

Using "higgsfield-marketplace-cards". Create product images for a premium skincare serum using my reference photo.

Expected outcome:

Marketplace cards ready: Main image, infographic, multi-angle, detail, lifestyle, and package-content links.

Using "higgsfield-marketplace-cards". Create A+ modules for a reusable water bottle.

Expected outcome:

Marketplace cards ready: Hero, pain points, features, ingredients, efficacy, usage, and endorsement links.

Security Audit

Critical
v5 • 7/23/2026 Open versioned report

The remote installation instruction pipes an unpinned script from a mutable branch directly into a shell, creating a critical supply-chain execution risk. Other backtick detections are Markdown formatting, while user-derived command arguments lack explicit shell-safety guidance.

1
Files scanned
89
Lines analyzed
1
Review items
0
False positives ignored

Confirmed security concerns (2)

Critical
Pipe to shell pattern
1. If `higgsfield` is not on `$PATH`, install it by running the official installer with Bash: `curl
The skill explicitly instructs piping a remotely downloaded script from a mutable branch into sh. This executes unverified upstream content with the agent's privileges.
Medium
User-Controlled Shell Arguments Lack Safety Rules
The skill builds a shell command from user requests but does not require structured argument passing, escaping, or rejection of shell substitutions.
Lines 66-68 direct command construction from user intent and include multiple free-text values. No argument-safety requirement appears in those instructions.
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Low
Hardcoded URL
1. If `higgsfield` is not on `$PATH`, install it by running the official installer with Bash: `curl
The URL targets a mutable branch and supplies a script for immediate execution. A repository compromise or upstream change could deliver arbitrary code.

Detected Patterns

Pipe to shell pattern
Audited by: codex View Audit History →
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/higgsfield-ai-higgsfield-marketplace-cards/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/higgsfield-ai-higgsfield-marketplace-cards/security.svg)](https://skillstore.io/skills/higgsfield-ai-higgsfield-marketplace-cards?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/higgsfield-ai-higgsfield-marketplace-cards?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/higgsfield-ai-higgsfield-marketplace-cards/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/higgsfield-ai-higgsfield-marketplace-cards.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA · BibTeX · CFF)

APA citation

higgsfield-ai. (2026). higgsfield-marketplace-cards security audit report (audit version 5) [Author version 0.12.0]. Skillstore. https://skillstore.io/skills/higgsfield-ai-higgsfield-marketplace-cards/audits/5

BibTeX citation

@techreport{higgsfield-ai-higgsfield-ai-higgsfield-marketplace-cards-2026, author = {higgsfield-ai}, title = {higgsfield-marketplace-cards security audit report (audit version 5)}, institution = {Skillstore}, year = {2026}, number = {5}, url = {https://skillstore.io/skills/higgsfield-ai-higgsfield-marketplace-cards/audits/5}, note = {Author version 0.12.0} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "higgsfield-marketplace-cards security audit report (audit version 5)" version: "0.12.0" type: report authors: - name: "higgsfield-ai" date-released: "2026-07-23" url: "https://skillstore.io/skills/higgsfield-ai-higgsfield-marketplace-cards/audits/5" identifiers: - type: other value: "skillstore:higgsfield-ai-higgsfield-marketplace-cards:audit:5" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
100
Maintainability
87
Content
67
Community
91
Spec Compliance

What You Can Build

Launch a New Listing

Generate a main image and five secondary images from product details and a reference photo.

Build A+ Content

Create coordinated feature, ingredient, usage, efficacy, and endorsement modules for a product detail page.

Produce Client Asset Sets

Generate a full listing set with consistent brand context and visual direction.

Try These Prompts

Create a Main Image
Create one marketplace main image for [product]. Use [reference image] and emphasize [important visible qualities].
Create Product Images
Create a marketplace product image set for [product]. Use [reference image], category [category], and visual style [style].
Create A+ Modules
Create A+ content for [product]. Include brand context [context], key features [features], usage [instructions], and verified benefits [benefits].
Extend an Existing Main Image
Use completed main image job [job ID]. Create [asset types] with category [category], brand context [context], and visual style [style].

Best Practices

  • Provide a clear product image whenever possible.
  • State the product category, brand context, and preferred visual style.
  • Verify all claims and marketplace requirements before publishing generated assets.

Avoid

  • Do not use this skill for video, generic photography, or character training.
  • Do not request unsupported or unverified product claims.
  • Do not execute remote installers without verification and explicit approval.

Frequently Asked Questions

What image sets can this skill create?
It can create a main image, product images, A+ modules, a full set, or a custom asset subset.
Does it need a product image?
A product image is preferred. Clear text details can be sufficient when the product and listing intent are unambiguous.
Can it use an existing generated main image?
Yes. Provide a completed main image job identifier and request supported secondary or A+ assets.
Does it guarantee marketplace compliance?
No. The backend applies marketplace references, but users must verify current platform rules before publishing.
What account setup is required?
The Higgsfield CLI must be installed, and the user must authenticate with a Higgsfield account.
What does the skill return?
It returns short labels with links to ready images. Internal prompts, model names, and job identifiers are hidden by default.

Developer Details

License

MIT

Author version

v0.12.0

Skillstore revision

r2

Ref

c43861a65bb95efcae259cd161c9d6f4dc7eec6f

Maintenance freshness

7/25/2026

Usage

4 downloads · 8 views

File structure

📄 SKILL.md