brand-context
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external websites to automatically draft brand documentation, which creates a surface for potential indirect prompt injection.
- Ingestion points: The skill uses
firecrawl_urls_scrapeandweb_scrape_pageto fetch content from user-provided URLs. - Boundary markers: The instructions mandate that the agent marks unverified content and requires a human review step before any files are saved.
- Capability inventory: The skill uses
create_fileandedit_filetools to persist the documentation to the agent's local file system. - Sanitization: A 'Quality gate' is defined to prevent the fabrication of data and ensures that all claims are verified by the user.
- [COMMAND_EXECUTION]: The skill utilizes network-based tools including
firecrawl_urls_scrapeandfirecrawl_branding_extractto gather data via the vendor's infrastructure at hyperfx.ai.
Audit Metadata