brand-voice-analyzer

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources and local files, which could contain malicious instructions designed to subvert the agent's behavior.
  • Ingestion points: Data is collected from external websites using WebFetch and WebSearch, and from local files using Glob and Read as specified in SKILL.md and references/edge-cases.md.
  • Boundary markers: The instructions do not define clear delimiters or include warnings to ignore instructions within the analyzed content.
  • Capability inventory: The skill possesses capabilities like Write, Edit, and Bash, which could be misused if the agent is successfully injected.
  • Sanitization: There are no documented procedures for sanitizing or validating external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 07:25 AM
Security Audit — agent-trust-hub — brand-voice-analyzer