brand-os-architect

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as a structured prompt for strategic brand development. It provides templates for positioning, voice, and visual systems without executing code or requesting sensitive permissions.
  • [EXTERNAL_DOWNLOADS]: The skill contains references to external educational and industry sources (e.g., paulgraham.com, a16z.com, cutestudies.org). These are treated as neutral background information for the agent and do not involve automated downloads or script execution.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes user-supplied assets (websites, docs, screenshots) to extract brand evidence, it includes strong boundary instructions ('Separate evidence from recommendations', 'Label unsupported assumptions', 'Preserve existing brand truth') which mitigate the risk of the agent being misled by instructions embedded in that data.
  • [CREDENTIALS_SAFE]: There are no hardcoded secrets or requests for API keys. The skill focuses on public brand identity rather than technical infrastructure.
  • [COMMAND_EXECUTION]: The skill does not contain any shell commands, subprocess calls, or system-level operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:43 PM
Security Audit — agent-trust-hub — brand-os-architect