brand-discovery
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill manages interview progress by persisting data to the local file system (e.g.,
state.jsonand files in themodules/andfounders/directories). It mitigates file system risks by explicitly instructing the agent to validate theoutputPathandparticipantidentifiers, specifically rejecting path traversal segments (e.g.,..) and invalid characters. - [SAFE]: The skill possesses an indirect prompt injection surface as it ingests user-provided interview answers. However, it treats this data as content for structured markdown templates (
## Rawand## Synthesissections) and lacks high-risk capabilities like network access or shell execution that could be exploited via malicious input. - [SAFE]: No evidence of prompt injection, obfuscation (Base64, hex encoding, or hidden characters), or unauthorized data exfiltration was found. The instructions are logically consistent with the stated purpose of professional brand discovery.
Audit Metadata