market-brand
Pass
Audited by Gen Agent Trust Hub on Apr 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a risk of indirect prompt injection because it is designed to ingest and analyze untrusted data from external sources. Ingestion points: Step 1 involves gathering source material from external homepages, about pages, and social media profiles. Boundary markers: The instructions do not define delimiters or provide 'ignore instructions' warnings for the fetched content. Capability inventory: The skill utilizes page reading tools to process external content and has the capability to generate comprehensive documentation in BRAND-VOICE.md. Sanitization: No sanitization or filtering of external content is specified. This lack of boundaries could allow malicious instructions embedded in a target website to influence the agent's behavior.
- [SAFE]: No evidence of credential theft, hardcoded secrets, or unauthorized network exfiltration was found. The skill appears to function as a legitimate brand analysis tool.
Audit Metadata