pe-brand-assets

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional, focusing on the generation of SVG assets within a local development environment. It does not perform network operations, download external scripts, or attempt to access sensitive system credentials.
  • [PROMPT_INJECTION]: The skill includes constraints that prevent the agent from inventing brand values, requiring it to strictly follow documented project guidelines. This acts as a functional safeguard against hallucinated or unauthorized output.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a defined attack surface as it processes external data.
  • Ingestion points: Reads from DESIGN.md, style guides, and the brand/ folder (SKILL.md).
  • Boundary markers: Absent; the skill does not explicitly use delimiters to separate brand data from execution instructions.
  • Capability inventory: Authoring SVG code and exporting assets to PNG (SKILL.md).
  • Sanitization: Absent.
  • Risk Assessment: While the skill reads untrusted project files, the potential impact is limited to the visual appearance of generated assets. No high-risk capabilities are exposed to this data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:51 PM
Security Audit — agent-trust-hub — pe-brand-assets