brandkit

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a structured framework for visual identity exploration, focusing on art direction strategies and aesthetic consistency without employing risky coding patterns.
  • [COMMAND_EXECUTION]: The script scripts/brandkit.py uses subprocess.run to call external identity tools and image generators (e.g., gpt-image-2, nano-banana, and the design-tokens CLI). These calls are strictly scoped to specific local script paths within the agent's known environment, preventing arbitrary shell command execution.
  • [DATA_EXPOSURE]: The skill accesses project-specific files like jtbd.json and design.tokens.json to derive brand strategies. This interaction is limited to project context and does not access sensitive system directories, environment variables, or user credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 09:32 PM
Security Audit — agent-trust-hub — brandkit