brainstorm

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to investigate existing project files, code, and documentation to build context for its analysis. This creates an attack surface where malicious instructions embedded in these files could influence the agent's behavior.
  • Ingestion points: The skill reads local project files, existing code, other skills, and documents during the "Entendimento" (Understanding) phase (Phase 1).
  • Boundary markers: The agent uses a confirmation mechanism for specialized lenses and an explicit "brainstorm mode" declaration, but there are no defined delimiters or sanitization steps for the data read from the project.
  • Capability inventory: The skill has the ability to write files (brainstorm documentation in markdown) and perform external network lookups via web search.
  • Sanitization: There is no mention of filtering or escaping content ingested from project files before it is processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill performs external lookups using web searches and specialized documentation tools to verify information regarding library versions, framework stability, and compatibility. This is part of its "Protocol of Rigor" to ensure technical accuracy and avoid relying on potentially outdated model memory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:05 PM
Security Audit — agent-trust-hub — brainstorm