brand-guide
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs legitimate analysis of brand assets provided by the user to extract hex codes, typography, and brand voice guidelines. It does not attempt to access sensitive system files or execute unauthorized commands.
- [PROMPT_INJECTION]: The skill ingests untrusted data from external websites and user-provided files, representing an indirect prompt injection surface.
- Ingestion points: Live site URLs, logo files, and brand decks identified in Gate 1 and Gate 2.
- Boundary markers: Absent; there are no specific instructions to ignore embedded commands within the analyzed brand materials.
- Capability inventory: The skill produces a
DESIGN.mdfile but lacks dangerous capabilities such as arbitrary code execution, file system modification (outside of the output), or unauthorized data transmission. - Sanitization: No sanitization or validation of the ingested content is specified.
Audit Metadata