brand-voice
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill's primary function involves processing untrusted external data, which could contain malicious instructions designed to manipulate the generated brand voice profile or the agent's behavior.
- Ingestion points: Data enters the context through user-provided content in 'Extract' mode and website data fetched via the Exa MCP tool in 'Auto-Scrape' mode.
- Boundary markers: The instructions lack explicit delimiters or 'ignore embedded instructions' warnings when processing this external content.
- Capability inventory: The skill writes analysis results to
brand/voice-profile.md, which is subsequently read by other skills in the ecosystem, creating a propagation path for potentially injected instructions. - Sanitization: No validation or sanitization of the fetched external content is described in the skill's logic.
Audit Metadata