review-brand

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for internal brand and copy reviews. It operates by reading local project files and returning a summary table. No risky operations such as network access, credential handling, or code execution were identified.
  • [COMMAND_EXECUTION]: The skill does not contain any shell commands or subprocess execution patterns. It explicitly states it should only report findings and never edit or refactor code.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the repository (brand documentation and code diffs). While this presents a surface for indirect prompt injection, the risk is mitigated by the skill's lack of write/execute capabilities and its strict requirement to return a specific output format.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 10:00 PM
Security Audit — agent-trust-hub — review-brand