thirds-brand-kit
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied brand details including names, color codes, tone guidance, and media files (logos, fonts). This ingestion of user-controlled data is a standard functional requirement for brand kit management. The skill provides clear instructions to use only user-provided assets and includes defensive guidance for the agent to avoid generating unauthorized content.
- [DATA_EXPOSURE]: The skill documentation includes explicit security instructions for the agent, such as advising the user to store API keys in a secure secret store rather than chat or files. It also instructs the agent to keep file bytes and asset IDs private, which demonstrates proactive security posture for handling brand media.
Audit Metadata