pe-brand-assets
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely instructional, focusing on the generation of SVG assets within a local development environment. It does not perform network operations, download external scripts, or attempt to access sensitive system credentials.
- [PROMPT_INJECTION]: The skill includes constraints that prevent the agent from inventing brand values, requiring it to strictly follow documented project guidelines. This acts as a functional safeguard against hallucinated or unauthorized output.
- [INDIRECT_PROMPT_INJECTION]: The skill has a defined attack surface as it processes external data.
- Ingestion points: Reads from
DESIGN.md, style guides, and thebrand/folder (SKILL.md). - Boundary markers: Absent; the skill does not explicitly use delimiters to separate brand data from execution instructions.
- Capability inventory: Authoring SVG code and exporting assets to PNG (SKILL.md).
- Sanitization: Absent.
- Risk Assessment: While the skill reads untrusted project files, the potential impact is limited to the visual appearance of generated assets. No high-risk capabilities are exposed to this data.
Audit Metadata