skills/promovaweb/brandfy/brandfy-voz/Gen Agent Trust Hub

brandfy-voz

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: No security issues were detected. The skill consists exclusively of markdown instructions and YAML configuration for documenting linguistic patterns, with no associated scripts or binary files.\n- [DATA_EXPOSURE]: The skill directs the agent to read brand-specific files such as BRAND.md, .brandfy/mvp-context.json, and .brandfy/interview.json. This access is restricted to the current project's context and does not involve accessing sensitive system directories or private credentials.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface through its reliance on external project files which could contain untrusted content. However, the risk is minimal as the skill lacks high-impact capabilities (e.g., network access or shell execution) that could be exploited via injection.\n
  • Ingestion points: Reads content from BRAND.md and .brandfy/ JSON files (SKILL.md).\n
  • Boundary markers: Absent.\n
  • Capability inventory: Read local files; write analysis to brand/voice.md. No network, shell, or dynamic execution capabilities.\n
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 12:07 PM
Security Audit — agent-trust-hub — brandfy-voz