brandfy-estrategia

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from several project files that may contain untrusted content, creating a potential surface for indirect prompt injection. * Ingestion points: The instructions in SKILL.md read from .brandfy/brief.md, .brandfy/mvp-context.json, .brandfy/asset-brief.md, BRAND.md, and .brandfy/interview-summary.md. * Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the ingested files. * Capability inventory: The agent has capabilities to read from and write to the local file system (specifically brand/strategy.md and .brandfy/strategy.md). * Sanitization: No sanitization, escaping, or validation logic is defined for the content extracted from the ingested files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 12:08 PM
Security Audit — agent-trust-hub — brandfy-estrategia