afa-scale

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data in the user_request field which presents a surface for indirect prompt injection.
  • Ingestion points: user_request field in the context contract (SKILL.md).
  • Boundary markers: The skill relies on platform-level protocols and a structured output format, though explicit delimiters for user input are not present in the code.
  • Capability inventory: Orchestrates routing to other worker skills and maintains state by writing to the ./brand-brain/ directory. It does not possess high-privilege capabilities like shell execution.
  • Sanitization: There is no evidence of specific sanitization for the user-provided request data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 04:40 PM
Security Audit — agent-trust-hub — afa-scale