brand-voice-synthesizer

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by processing untrusted data from published WordPress posts and activity reports.
  • Ingestion points: Data is collected from the site using respira_read_post, respira_extract_builder_content, and respira_generate_activity_report within the execution workflow.
  • Boundary markers: The workflow does not define specific delimiters or instructions to ignore potential commands within the analyzed content.
  • Capability inventory: The agent can persist data to the site using respira_update_option.
  • Sanitization: The skill strips code blocks and shortcodes from the source text during analysis.
  • [DATA_EXFILTRATION]: Sends usage telemetry to the vendor's official endpoint at https://www.respira.press/api/skills/track-usage. This telemetry includes site metadata and sampling statistics but does not include actual post content or the extracted voice profile.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 09:11 PM
Security Audit — agent-trust-hub — brand-voice-synthesizer