brand-kit
Warn
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of shell commands including
curl,sips,file, andmd5to retrieve, identify, and modify files from external web sources. - [DYNAMIC_EXECUTION]: The agent is instructed to execute a multi-line Python script provided via a shell heredoc in
references/manifest.mdto perform file verification. Additionally, the instructions require the agent to modify the local project filegen.pyand execute it to finalize the canvas layout. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and parses content from arbitrary external websites (marketing sites, newsrooms, app stores) which serves as a vulnerability surface for malicious instructions.
- Ingestion points: Network requests in
references/sources.mdfetch HTML content and API data from external domains into the agent's context. - Boundary markers: There are no specific delimiters or instructions to ignore embedded commands within the fetched content.
- Capability inventory: The skill utilizes
curl,python3, and system utilities likesipsandfileto process the data. - Sanitization: Verification is focused on file integrity (format, dimensions, size) rather than sanitizing the text content for potential prompt injection attacks.
- [REMOTE_CODE_EXECUTION]: The skill utilizes a piped execution pattern (
curl | python3) to retrieve and process data from the Apple iTunes API. While the source is a well-known service, this pattern remains high-risk as it executes remote data directly.
Audit Metadata