skills/sfrmrc/skills/company-logos/Gen Agent Trust Hub

company-logos

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references runtime dependencies from well-known and trusted providers including Google Fonts, Cloudflare (cdnjs), and Iconify. These are standard resources for web development and present no security risk.
  • [COMMAND_EXECUTION]: The provided demo (demo/index.html) uses a sandboxed iframe with restricted permissions (sandbox="allow-scripts") and a strict Content Security Policy (CSP) to ensure safe rendering of the example content.
  • [DATA_EXPOSURE]: No sensitive file paths, environment variables, or hardcoded credentials were detected. The skill focuses solely on UI design and asset presentation.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests brand names to fetch logos, it uses clear boundary markers and specific formatting instructions (64x64 monochrome) to prevent data from influencing agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 01:36 PM
Security Audit — agent-trust-hub — company-logos