brand-voice
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a shell script for a daily version check.
- Evidence: The script uses
findto check for a local timestamp file (~/.claude/.foundry-version-checked) andcurlto fetch the current version fromhttps://foundry.thehorizonfoundry.com/api/version. - Purpose: This is a documented rate-limited check to notify the user if a newer version of the suite is available.
- [EXTERNAL_DOWNLOADS]: The skill fetches a brand template and documentation from GitHub if local copies are unavailable.
- Evidence: URLs target
https://raw.githubusercontent.com/horizon-foundry/foundry/. - Purpose: Retrieval of static documentation and templates from the official project repository.
- [INDIRECT_PROMPT_INJECTION]: The skill operates by reading and applying instructions from a local
BRAND.mdfile, which creates a potential surface for indirect injection if that file is compromised. - Ingestion points:
BRAND.mdis read to determine the brand voice mode and content. - Boundary markers: No specific delimiters are used to wrap the content of
BRAND.mdwhen it is processed. - Capability inventory: The skill uses the ingested rules to write and review user-facing copy; no critical capabilities (like remote execution) are triggered by the brand file content.
- Sanitization: None. Content from the brand file is treated as authoritative for stylistic decisions.
Audit Metadata