brandkit-setup
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads and installs various agent extensions from external GitHub repositories. This includes fetching guidelines from the Vercel Labs official repository and tools from the Cursor and Higgsfield AI ecosystems.
- [COMMAND_EXECUTION]: The skill employs shell commands to audit the local environment (Node.js, Python, Git) and automate the installation of dependencies like the Higgsfield CLI and the Pillow library.
- [PROMPT_INJECTION]: The setup process introduces an indirect prompt injection surface through the ingestion of external skill code. 1. Ingestion points: External GitHub repositories. 2. Boundary markers: None identified. 3. Capability inventory: Shell command execution and global package installation. 4. Sanitization: None detected.
Audit Metadata