brand-voice-extractor

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill contains no executable scripts or code files. It functions as a structured prompt for the AI agent.
  • [PROMPT_INJECTION]: The skill ingests and analyzes content from user-provided external URLs, creating an indirect prompt injection surface. 1. Ingestion points: Content is fetched from external URLs in Phase 2 of SKILL.md. 2. Boundary markers: The instructions lack specific delimiters or warnings to isolate fetched content from analysis instructions. 3. Capability inventory: The skill uses WebFetch for reading and generates a text-based Markdown report. 4. Sanitization: There is no logic to sanitize or filter potential instructions embedded in the analyzed website content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 03:06 PM
Security Audit — agent-trust-hub — brand-voice-extractor