ip-as-logo

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions in SKILL.md direct the agent to read local project context, including README files, product documentation, and package metadata, to infer brand personality and audience. This data ingestion process represents an attack surface for indirect prompt injection, as malicious content within these project files could influence the agent's behavior or output directions.
  • Ingestion points: SKILL.md (Step 2) identifies the README, product docs, package/app metadata, landing-page copy, manifests, and design tokens as sources for context.
  • Boundary markers: No specific boundary markers or sanitization instructions are provided to the agent for handling this external data.
  • Capability inventory: The agent uses image generation tools and may request API keys from the user.
  • Sanitization: None detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 09:59 AM
Security Audit — agent-trust-hub — ip-as-logo