brandfy-identidade-visual
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from local brand-related files without explicit sanitization or delimiters.
- Ingestion points: Uses content from
.brandfy/interview.json,.brandfy/asset-brief.md, and.brandfy/interview-summary.md. - Boundary markers: No specific delimiters or boundary markers are instructed for use during data ingestion.
- Capability inventory: The skill reads and writes to several local brand configuration files (BRAND.md, CHROMATIC.md, visual-direction.md) and executes other internal skills ($brandfy-design-tokens, $brandfy-tipografia-web).
- Sanitization: There is no evidence of sanitization or input validation for the ingested data.
Audit Metadata