skills/broomva/skills/brand-icons/Gen Agent Trust Hub

brand-icons

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. Untrusted data enters the agent context through the 'title' and 'subtitle' parameters defined in 'skill.json', as well as project files scanned during the 'audit' workflow. The instructions lack boundary markers or delimiters to isolate this untrusted content. The agent is directed to use this data with powerful system capabilities, including file writing and executing shell tools like ImageMagick, without any defined sanitization or validation steps to prevent malicious instructions embedded in the input from influencing behavior.\n- [COMMAND_EXECUTION]: The workflows instruct the AI agent to map user intents to concrete shell commands for tools like 'magick', 'convert', 'sharp', and 'rsvg-convert'. Since these commands are constructed using dynamic user-provided strings ('title', 'subtitle') without explicit guidance on shell escaping or sanitization, they represent a potential command injection surface.\n- [NO_CODE]: This is a latent-only skill that contains no scripts, binaries, or source code. All described behaviors are instructions for the AI agent to execute using tools already present in the runtime environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 03:33 PM
Security Audit — agent-trust-hub — brand-icons