brand-voice-enforcement

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • Category 1 (Prompt Injection): No instructions designed to override agent safety or reveal system prompts were found. The skill uses standard instructional language to manage content generation behaviors.
  • Category 2 (Data Exposure/Exfiltration): No hardcoded credentials, sensitive file access (e.g., SSH keys, AWS creds), or network exfiltration patterns were detected. The skill reads from local .claude/ and references/ directories for configuration and documentation, which is standard for skill operations.
  • Category 3 (Obfuscation): No encoded strings (Base64, Hex), homoglyphs, or zero-width characters were found. The content is plain-text markdown.
  • Category 4 (External Downloads/RCE): The skill does not perform external downloads (curl, wget) or execution of remote scripts. It uses local references exclusively.
  • Category 8 (Indirect Prompt Injection): While the skill processes user-provided content and brand guidelines (Category 8 attack surface), it does not have the high-level capabilities (like network access or arbitrary command execution) that typically elevate this risk beyond a baseline state.
  • Category 11 (Dynamic Context Injection): No dynamic context placeholders (exclamation mark and backticks) were identified in the SKILL.md file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:16 AM