source-brand-assets

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the mkdir command to create directory structures and the curl command to download image and vector files from the internet.
  • [EXTERNAL_DOWNLOADS]: Brand assets are fetched from public sources and well-known content delivery networks, including Wikimedia Commons, Brandfetch, Fastly, and Akamai. The skill uses a custom User-Agent to ensure asset retrieval from these public endpoints.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from web search results and file content, creating a surface for indirect prompt injection. This risk is addressed by the workflow's requirement for visual verification of all downloaded assets.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 03:06 PM
Security Audit — agent-trust-hub — source-brand-assets