brand-positioning
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses local files (brand.yaml, context.md) for brand context, which is a standard and safe operation for this use case. No sensitive system paths are accessed.
- [PROMPT_INJECTION]: The skill processes external file content, creating an indirect prompt injection surface. This is considered safe as the skill lacks high-privilege tools (e.g., shell access or network requests) to exploit such an injection. * Ingestion points: brand.yaml, context.md (SKILL.md). * Boundary markers: Absent. * Capability inventory: None detected. * Sanitization: Absent.
Audit Metadata