brand-voice
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by ingesting untrusted data from external sources such as X posts, articles, and emails for stylistic analysis. Ingestion points: SKILL.md (Gather 5 to 20 samples, x-api, site copy). Boundary markers: Absent. Capability inventory: SKILL.md (read-only x-api access). Sanitization: Absent. The risk is considered safe as the analysis is focused exclusively on linguistic features and the skill lacks capabilities to execute embedded commands or perform dangerous operations.
- [COMMAND_EXECUTION]: The skill references an 'x-api' tool to retrieve social media content. This is a specific tool invocation for the skill's primary function and does not involve arbitrary command execution or privilege escalation.
Audit Metadata