magic-hour-brand-kit
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external brand briefs, image files, and user-supplied requirements, which provides a surface for indirect prompt injection where malicious instructions could be embedded in user data.\n
- Ingestion points: Requirements are extracted from supplied files and prior context as specified in SKILL.md.\n
- Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following instructions embedded within the brand data.\n
- Capability inventory: The skill has the ability to write files (brand.md), use AI generation/editing tools, retrieve account data, and download files from URLs.\n
- Sanitization: No explicit content sanitization or validation logic is defined for the incoming data.\n- [EXTERNAL_DOWNLOADS]: The skill instructions include downloading brand assets and project outputs from the official vendor domain (magichour.ai) and referencing documentation on GitHub. These operations are associated with the core functionality of the skill and target the vendor's own infrastructure.
Audit Metadata