brand
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external brand documentation and assets, creating a surface for indirect prompt injection if those files contain malicious instructions.\n- Ingestion points: The skill is instructed to inspect existing brand guidance, identity assets, and message evidence as described in SKILL.md and references/asset-organization.md.\n- Boundary markers: Absent; there are no specific instructions to use delimiters or ignore embedded instructions when reading external files.\n- Capability inventory: The skill has file modification capabilities (moving, renaming, writing) in references/asset-organization.md and mentions technical asset inspection using the 'file' command in references/approval-checklist.md.\n- Sanitization: Absent; no specific validation or escaping of ingested content is defined.
Audit Metadata