brand-kit
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documents how to fetch branding information from the vendor's API at
brand.replynodes.com. These requests retrieve JSON data representing visual identity assets and do not involve executable code. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external metadata (such as site descriptions and names) from public websites. This introduces a surface for indirect prompt injection. However, the instructions explicitly guide the agent to treat fetched content as data rather than instructions, providing a basic boundary against accidental obedience to embedded strings.
Audit Metadata