build-a-brand
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches font files from the official Google Fonts GitHub repository (github.com/google/fonts). This is a well-known and trusted source for web assets.\n- [COMMAND_EXECUTION]: Employs a suite of MCP tools (mcp__pika__*) to perform image generation and PDF compilation. These operations are essential to the skill's primary function and are performed within the expected tool boundaries.\n- [DATA_EXFILTRATION]: Writes the final generated brand assets to the user's desktop. This is a legitimate delivery mechanism for a design tool and does not involve sending sensitive user information to unauthorized external servers.\n- [PROMPT_INJECTION]: While the skill processes external inputs like URLs and user ideas, it utilizes a highly structured multi-stage workflow and mandatory visual quality gates to mitigate the risk of indirect prompt injection.
Audit Metadata