brand-voice

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes untrusted external content (X posts, articles, emails) to generate a voice profile.\n
  • Ingestion points: SKILL.md specifies gathering samples from various external sources and using x-api to pull posts.\n
  • Boundary markers: The instructions lack specific delimiters or "ignore" commands for content within the source samples to prevent the agent from following instructions embedded in the source material.\n
  • Capability inventory: The skill uses x-api for network reads and saves profile data to the workspace or memory, which then influences downstream content generation skills.\n
  • Sanitization: The skill does not describe any sanitization or validation for the source text before processing.\n- [DATA_EXFILTRATION]: The skill is designed to process potentially sensitive communications, including outbound emails and direct messages (DMs). While the persistence rules attempt to minimize risk by avoiding repo-tracked files by default, the agent still handles and stores private user data in its session context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — brand-voice