brandkit
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided brand definitions to generate configuration files and design tokens on the local filesystem.
- Ingestion points: User input defining brand positioning, colors, and typography during the definition and audit steps in SKILL.md.
- Boundary markers: The agent is guided by a structured 10-step workflow, and mathematical calculations are offloaded to a dedicated script (
scripts/tokens.py) for deterministic results. - Capability inventory: The skill involves writing a
brand.jsonconfiguration file and executing a Python tool that generatestokens.cssandtokens.jsonfiles in an output directory. - Sanitization: The
scripts/tokens.pyscript includes validation logic to ensure color values are valid hex codes and that scale parameters are positive numbers, mitigating basic malformed data risks.
Audit Metadata