brand-discovery

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes user-supplied brand information stored in local Markdown files across multiple sessions to maintain interview continuity.
  • Ingestion points: Reads module files (e.g., modules/10_purpose-why.md) and state.json from the local brand-identity directory in the SKILL.md start protocol.
  • Boundary markers: The module files use Markdown headers (## Raw) to separate user input, but there are no explicit instructions for the agent to ignore potentially malicious commands that might be embedded in the user's past verbatim responses.
  • Capability inventory: The skill performs local file writes to state.json, modules/*.md, and founders/*.md to record interview progress.
  • Sanitization: The skill implements strong validation for participant names (alphanumeric and hyphens only), module filenames (fixed sequence 10-90), and output paths (absolute paths only, rejecting .. segments) in the Multi-founder mode section of SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — brand-discovery