brand-voice
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is the creation of brand documentation and templates. It follows established best practices for data persistence within the specified project structure.\n- [COMMAND_EXECUTION]: The skill includes a bash utility,
scripts/verify.sh, designed for structural linting of the voice guides. Analysis of the script confirms it is a read-only tool using standard Unix utilities (grep, sed). It contains no network exfiltration or privilege escalation patterns.\n- [COMMAND_EXECUTION]: Thescripts/verify.shscript includes defensive coding measures, specifically sanitizing 'ban list' terms extracted from user documents by filtering for alphabetic characters only. This prevents potential regex or command injection when the terms are used in subsequent grep operations.\n- [PROMPT_INJECTION]: While the skill ingests untrusted user input to generate voice guides, the risk of indirect prompt injection is minimal. The skill provides clear structural boundaries via templates, and the validation script treats user data as static text for pattern matching without executing it.
Audit Metadata