design-brand-visual
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data exfiltration were detected. The skill operates within its stated purpose of brand visual coordination.
- [INDIRECT_PROMPT_INJECTION]: The skill processes local project files to extract branding constraints, representing an ingestion surface for indirect prompt injection. 1. Ingestion points: Reads DESIGN.md, CSS token files, and brand identity documents. 2. Boundary markers: Absent; the skill does not use specific delimiters for ingested content. 3. Capability inventory: Delegates image generation to the moai-media:media-higgsfield-core tool. 4. Sanitization: Absent; while it converts negative descriptions to positive ones, it does not sanitize or escape the input data.
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill references the official Higgsfield domain and GitHub repository for documentation and manual generation fallbacks. These are recognized as well-known service references related to the skill's primary function.
Audit Metadata