source-brand-assets
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the mkdir command to create directory structures and the curl command to download image and vector files from the internet.
- [EXTERNAL_DOWNLOADS]: Brand assets are fetched from public sources and well-known content delivery networks, including Wikimedia Commons, Brandfetch, Fastly, and Akamai. The skill uses a custom User-Agent to ensure asset retrieval from these public endpoints.
- [PROMPT_INJECTION]: The skill ingests untrusted data from web search results and file content, creating a surface for indirect prompt injection. This risk is addressed by the workflow's requirement for visual verification of all downloaded assets.
Audit Metadata