skills/ssheleg/super-ux/brand-voice/Gen Agent Trust Hub

brand-voice

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the execution of a local Python script docs/brand/lint.py to validate brand consistency across the project files.
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to run npx sshlg-skills humanizers to list or install external humanization modules. This involves downloading and executing code from the npm registry. The package name sshlg-skills is a vendor-owned resource associated with the author ssheleg.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from the project's foundation documents (personas, journeys, stakes) and interface strings to generate brand guidelines. It lacks explicit sanitization or boundary markers for this ingested content, creating a surface where instructions embedded in project data could potentially influence agent behavior.
  • [PRIVILEGE_ESCALATION]: No privilege escalation patterns were detected.
  • [DATA_EXFILTRATION]: No data exfiltration patterns or network requests to untrusted domains were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:57 AM
Security Audit — agent-trust-hub — brand-voice