brand-kit

Warn

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of shell commands including curl, sips, file, and md5 to retrieve, identify, and modify files from external web sources.
  • [DYNAMIC_EXECUTION]: The agent is instructed to execute a multi-line Python script provided via a shell heredoc in references/manifest.md to perform file verification. Additionally, the instructions require the agent to modify the local project file gen.py and execute it to finalize the canvas layout.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and parses content from arbitrary external websites (marketing sites, newsrooms, app stores) which serves as a vulnerability surface for malicious instructions.
  • Ingestion points: Network requests in references/sources.md fetch HTML content and API data from external domains into the agent's context.
  • Boundary markers: There are no specific delimiters or instructions to ignore embedded commands within the fetched content.
  • Capability inventory: The skill utilizes curl, python3, and system utilities like sips and file to process the data.
  • Sanitization: Verification is focused on file integrity (format, dimensions, size) rather than sanitizing the text content for potential prompt injection attacks.
  • [REMOTE_CODE_EXECUTION]: The skill utilizes a piped execution pattern (curl | python3) to retrieve and process data from the Apple iTunes API. While the source is a well-known service, this pattern remains high-risk as it executes remote data directly.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 21, 2026, 03:56 PM
Security Audit — agent-trust-hub — brand-kit