ugc-brief

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses bash scripts to manage its environment, including checking for updates via rmbc-update-check and logging usage data via rmbc-analytics. These scripts are part of the tool's local installation and are used for maintenance and telemetry purposes.
  • [EXTERNAL_DOWNLOADS]: The skill provides a mechanism to open a YouTube video URL for a welcome introduction using the open command. This is a user-invocable action prompted through an interactive question.
  • [DATA_EXFILTRATION]: The skill includes an optional telemetry feature that logs usage data (skill name, product, tier). The code explicitly states that no code, prompts, or file paths leave the computer, and the user is provided with a one-time opt-in/opt-out prompt. Local configuration is stored in ~/.rmbc-skills/config.yaml.
  • [PROMPT_INJECTION]: No evidence of prompt injection, role-play bypasses, or instructions to ignore safety guidelines was found. The instructions focus on copywriting frameworks and creator brief generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 01:36 PM
Security Audit — agent-trust-hub — ugc-brief