skills/quantipixels/skills/brand/Gen Agent Trust Hub

brand

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external brand documentation and assets, creating a surface for indirect prompt injection if those files contain malicious instructions.\n- Ingestion points: The skill is instructed to inspect existing brand guidance, identity assets, and message evidence as described in SKILL.md and references/asset-organization.md.\n- Boundary markers: Absent; there are no specific instructions to use delimiters or ignore embedded instructions when reading external files.\n- Capability inventory: The skill has file modification capabilities (moving, renaming, writing) in references/asset-organization.md and mentions technical asset inspection using the 'file' command in references/approval-checklist.md.\n- Sanitization: Absent; no specific validation or escaping of ingested content is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 02:26 PM
Security Audit — agent-trust-hub — brand