brandfy-estrategia
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from several project files that may contain untrusted content, creating a potential surface for indirect prompt injection. * Ingestion points: The instructions in SKILL.md read from
.brandfy/brief.md,.brandfy/mvp-context.json,.brandfy/asset-brief.md,BRAND.md, and.brandfy/interview-summary.md. * Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the ingested files. * Capability inventory: The agent has capabilities to read from and write to the local file system (specificallybrand/strategy.mdand.brandfy/strategy.md). * Sanitization: No sanitization, escaping, or validation logic is defined for the content extracted from the ingested files.
Audit Metadata