brand-identity

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides comprehensive guidelines for brand identity creation without accessing sensitive system resources or performing unauthorized network operations. References to external schemas use official, well-known domains.
  • [COMMAND_EXECUTION]: The utility scripts/verify.sh is a safe, locally-run verification script. It utilizes the Python standard library for JSON parsing and mathematical calculations of contrast ratios, following best practices by verifying dependencies and performing only read-only operations on the targeted JSON file.
  • [PROMPT_INJECTION]: The skill processes user input to generate branding deliverables (e.g., design-tokens.json) consumed by subsequent skills. This surface is considered safe as it utilizes standard LLM generation and a read-only local validation tool.
  • Ingestion points: User prompts containing brand names and taglines.
  • Boundary markers: Absent in generated artifacts.
  • Capability inventory: File emission and read-only script execution.
  • Sanitization: Handled by standard agent output guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — brand-identity