brand-voice

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a shell script for a daily version check.
  • Evidence: The script uses find to check for a local timestamp file (~/.claude/.foundry-version-checked) and curl to fetch the current version from https://foundry.thehorizonfoundry.com/api/version.
  • Purpose: This is a documented rate-limited check to notify the user if a newer version of the suite is available.
  • [EXTERNAL_DOWNLOADS]: The skill fetches a brand template and documentation from GitHub if local copies are unavailable.
  • Evidence: URLs target https://raw.githubusercontent.com/horizon-foundry/foundry/.
  • Purpose: Retrieval of static documentation and templates from the official project repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by reading and applying instructions from a local BRAND.md file, which creates a potential surface for indirect injection if that file is compromised.
  • Ingestion points: BRAND.md is read to determine the brand voice mode and content.
  • Boundary markers: No specific delimiters are used to wrap the content of BRAND.md when it is processed.
  • Capability inventory: The skill uses the ingested rules to write and review user-facing copy; no critical capabilities (like remote execution) are triggered by the brand file content.
  • Sanitization: None. Content from the brand file is treated as authoritative for stylistic decisions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 05:47 PM
Security Audit — agent-trust-hub — brand-voice