alterlab-vcd-brand-identity
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a specialized persona ('BrandIdentityDesigner') and provides comprehensive instructions for branding tasks such as logo system design and brand book production. The instructions are aligned with the stated purpose and follow industry best practices for design workflows.
- [DATA_EXPOSURE]: The skill includes instructions to 'Read existing project files for context' and 'Search the web for competitor visual identities.' These are standard operational tasks for a branding assistant and do not involve access to sensitive system directories (~/.ssh, ~/.aws) or the exfiltration of credentials.
- [INDIRECT_PROMPT_INJECTION]: By reading external project files and performing web searches, the skill has an ingestion surface for indirect prompt injection. However, this is a functional requirement for the skill's purpose, and the skill does not define or request high-risk capabilities (such as shell execution or privileged system access) that would allow for an escalation of this risk beyond a standard baseline.
- [COMMAND_EXECUTION]: All outputs are specified as structured markdown files (e.g., {project}-brand-guidelines.md). There are no instructions for the agent to execute shell scripts, compile code, or modify system configurations.
Audit Metadata