brandfy-voz
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: No security issues were detected. The skill consists exclusively of markdown instructions and YAML configuration for documenting linguistic patterns, with no associated scripts or binary files.\n- [DATA_EXPOSURE]: The skill directs the agent to read brand-specific files such as
BRAND.md,.brandfy/mvp-context.json, and.brandfy/interview.json. This access is restricted to the current project's context and does not involve accessing sensitive system directories or private credentials.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface through its reliance on external project files which could contain untrusted content. However, the risk is minimal as the skill lacks high-impact capabilities (e.g., network access or shell execution) that could be exploited via injection.\n - Ingestion points: Reads content from
BRAND.mdand.brandfy/JSON files (SKILL.md).\n - Boundary markers: Absent.\n
- Capability inventory: Read local files; write analysis to
brand/voice.md. No network, shell, or dynamic execution capabilities.\n - Sanitization: Absent.
Audit Metadata