brand-context

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external websites to automatically draft brand documentation, which creates a surface for potential indirect prompt injection.
  • Ingestion points: The skill uses firecrawl_urls_scrape and web_scrape_page to fetch content from user-provided URLs.
  • Boundary markers: The instructions mandate that the agent marks unverified content and requires a human review step before any files are saved.
  • Capability inventory: The skill uses create_file and edit_file tools to persist the documentation to the agent's local file system.
  • Sanitization: A 'Quality gate' is defined to prevent the fabrication of data and ensures that all claims are verified by the user.
  • [COMMAND_EXECUTION]: The skill utilizes network-based tools including firecrawl_urls_scrape and firecrawl_branding_extract to gather data via the vendor's infrastructure at hyperfx.ai.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:29 AM
Security Audit — agent-trust-hub — brand-context