brand-voice

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill's primary function involves processing untrusted external data, which could contain malicious instructions designed to manipulate the generated brand voice profile or the agent's behavior.
  • Ingestion points: Data enters the context through user-provided content in 'Extract' mode and website data fetched via the Exa MCP tool in 'Auto-Scrape' mode.
  • Boundary markers: The instructions lack explicit delimiters or 'ignore embedded instructions' warnings when processing this external content.
  • Capability inventory: The skill writes analysis results to brand/voice-profile.md, which is subsequently read by other skills in the ecosystem, creating a propagation path for potentially injected instructions.
  • Sanitization: No validation or sanitization of the fetched external content is described in the skill's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 06:22 PM
Security Audit — agent-trust-hub — brand-voice