brandalf
Pass
Audited by Gen Agent Trust Hub on May 9, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches brand guidelines from a Vercel-hosted URL associated with the project. Vercel is a well-known cloud platform, and the activity is aligned with the skill's stated purpose.
- [PROMPT_INJECTION]: The skill utilizes a remote URL as a source of truth for instructions, creating an indirect prompt injection surface. Ingestion point: SKILL.md (remote URL). Boundary markers: Not present. Capability inventory: Limited to content generation and review tasks. Sanitization: Not specified for the remote content.
Audit Metadata