brand-guidelines
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to style external artifacts such as presentations or documents, which introduces a vulnerability surface where malicious instructions hidden in the input data could be processed by the agent. \n
- Ingestion points: The skill processes user-provided artifacts to apply visual styling (SKILL.md). \n
- Boundary markers: No specific delimiters or warnings for the agent to ignore embedded instructions are present. \n
- Capability inventory: The skill documentation indicates the use of formatting libraries like
python-pptxto modify files (SKILL.md). \n - Sanitization: There is no evidence of input validation or content sanitization. \n- [NO_CODE]: The skill contains markdown instructions and a license file but does not include any executable scripts or binary files.
Audit Metadata