muapi-brand-kit

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill orchestrates the generation of visual assets by instructing the agent to use the muapi CLI and curl commands. These commands are used as intended for image generation and task polling.
  • [DATA_EXFILTRATION]: The skill references the use of an API key ($MUAPI_API_KEY) for authentication with the api.muapi.ai endpoint. This is standard procedure for interacting with the service provided by the vendor and does not represent a data exfiltration risk.
  • [PROMPT_INJECTION]: The skill interpolates user-provided inputs into image generation prompts via template tags. While this represents a surface for indirect prompt injection, the risk is minimal as the input is used solely for visual content generation rather than logic control.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 02:04 PM
Security Audit — agent-trust-hub — muapi-brand-kit