brand-voice

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a local Python script (measure.py) and instructs the agent on its execution to verify text styling modes. This script is part of the skill source and performs static analysis on local text files.
  • [PROMPT_INJECTION]: The skill adapts its verbosity based on external configuration files such as CLAUDE.md and .claude/settings.json, representing an indirect prompt injection surface.
  • Ingestion points: Project configuration files CLAUDE.md and .claude/settings.json.
  • Boundary markers: No explicit delimiters are defined to isolate configuration data from instruction context.
  • Capability inventory: Utilizes the Read tool and local Python script execution.
  • Sanitization: The skill does not validate configuration inputs against a strict schema before adjusting its mode.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 06:07 AM
Security Audit — agent-trust-hub — brand-voice