muapi-brand-kit
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill orchestrates the generation of visual assets by instructing the agent to use the
muapiCLI andcurlcommands. These commands are used as intended for image generation and task polling. - [DATA_EXFILTRATION]: The skill references the use of an API key (
$MUAPI_API_KEY) for authentication with theapi.muapi.aiendpoint. This is standard procedure for interacting with the service provided by the vendor and does not represent a data exfiltration risk. - [PROMPT_INJECTION]: The skill interpolates user-provided inputs into image generation prompts via template tags. While this represents a surface for indirect prompt injection, the risk is minimal as the input is used solely for visual content generation rather than logic control.
Audit Metadata