brand-review
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [SAFE]: The skill provides a comprehensive framework for auditing brand voice and compliance using instructional logic. It does not include or execute any external scripts, binaries, or unexpected code modules.
- [PROMPT_INJECTION]: The skill is designed to process untrusted data from URLs and local files, which creates an inherent surface for indirect prompt injection. This risk is consistent with the skill's primary purpose of reviewing external content.
- Ingestion points:
SKILL.mdidentifies input sources as pasted text, file paths, and external URLs. - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' commands to isolate external content from the agent's instructions.
- Capability inventory: The skill utilizes the agent's standard capabilities for reading local files and fetching web content.
- Sanitization: No explicit instructions for sanitizing or validating external input are provided.
- [NO_CODE]: The skill consists entirely of markdown documentation and instructions, with no accompanying scripts, executable files, or configuration files that could introduce code-based vulnerabilities.
Audit Metadata