brand-kit

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documents how to fetch branding information from the vendor's API at brand.replynodes.com. These requests retrieve JSON data representing visual identity assets and do not involve executable code.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external metadata (such as site descriptions and names) from public websites. This introduces a surface for indirect prompt injection. However, the instructions explicitly guide the agent to treat fetched content as data rather than instructions, providing a basic boundary against accidental obedience to embedded strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:27 PM
Security Audit — agent-trust-hub — brand-kit