brandfy-identidade-visual

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from local brand-related files without explicit sanitization or delimiters.
  • Ingestion points: Uses content from .brandfy/interview.json, .brandfy/asset-brief.md, and .brandfy/interview-summary.md.
  • Boundary markers: No specific delimiters or boundary markers are instructed for use during data ingestion.
  • Capability inventory: The skill reads and writes to several local brand configuration files (BRAND.md, CHROMATIC.md, visual-direction.md) and executes other internal skills ($brandfy-design-tokens, $brandfy-tipografia-web).
  • Sanitization: There is no evidence of sanitization or input validation for the ingested data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 12:13 PM
Security Audit — agent-trust-hub — brandfy-identidade-visual