creative-direction

Pass

Audited by Gen Agent Trust Hub on May 9, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill references established brands like Stripe, Vercel, and Apple as benchmarks for aesthetic positioning, which is standard industry practice for creative development.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface by processing user-provided reference URLs. 1. Ingestion points: Reference URLs are used as inputs to calibrate the creative brief (SKILL.md). 2. Boundary markers: The workflow does not include specific delimiters or instructions to ignore embedded commands in the referenced web content. 3. Capability inventory: The skill performs file system writes to create a project BRIEF.md file. 4. Sanitization: There is no explicit process mentioned for validating or sanitizing content retrieved from external URLs before synthesis.
Audit Metadata
Risk Level
SAFE
Analyzed
May 9, 2026, 12:18 PM