visual-brand-extractor

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates entirely through natural language instructions for the agent to use its existing web-fetching tools. It does not include any executable scripts, remote downloads, or sensitive file access.
  • [COMMAND_EXECUTION]: The skill uses standard markdown and JSON output. The installation field in skill.meta.json uses a standard npx command for installation, which is a common pattern for skill distribution and does not pose an inherent risk in this context.
  • [DATA_EXFILTRATION]: While the skill fetches data from external URLs, it is restricted to public website branding information (CSS, fonts, HTML structure) as requested by the user. There are no patterns suggesting the exfiltration of private user data or credentials.
  • [PROMPT_INJECTION]: No attempts to override system prompts or bypass safety guidelines were found. The instructions are focused strictly on the stated purpose of brand extraction.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 03:05 PM
Security Audit — agent-trust-hub — visual-brand-extractor