design-brand-visual

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data exfiltration were detected. The skill operates within its stated purpose of brand visual coordination.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes local project files to extract branding constraints, representing an ingestion surface for indirect prompt injection. 1. Ingestion points: Reads DESIGN.md, CSS token files, and brand identity documents. 2. Boundary markers: Absent; the skill does not use specific delimiters for ingested content. 3. Capability inventory: Delegates image generation to the moai-media:media-higgsfield-core tool. 4. Sanitization: Absent; while it converts negative descriptions to positive ones, it does not sanitize or escape the input data.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill references the official Higgsfield domain and GitHub repository for documentation and manual generation fallbacks. These are recognized as well-known service references related to the skill's primary function.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 01:42 PM
Security Audit — agent-trust-hub — design-brand-visual