skills/yu-369/vibecurb/brandkit-gen/Gen Agent Trust Hub

brandkit-gen

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely focused on providing instructions and a multi-phase pipeline for creative identity design and image generation. It does not contain executable code or request sensitive permissions.
  • [COMMAND_EXECUTION]: The text contains references to terminal commands such as npm install kuro and browser URLs like app.kuro.dev. These are explicitly described as text elements to be included inside generated image mockups for realism and are not intended for execution by the AI agent on the host system.
  • [INDIRECT_PROMPT_INJECTION]: Phase 0 (Visual Reference Acquisition) involves ingesting user-provided images to extract aesthetic 'DNA'. While this introduces external data into the prompt generation process, the skill includes rigorous 'Anti-Slop' and 'Logo Originality' rules that act as negative constraints, and the skill's capabilities are restricted solely to image generation, minimizing the risk of exploitation.
  • [NO_CODE]: The skill's frontmatter and instructions explicitly state that it does not write code, and no scripting or automation capabilities were found within the provided content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 04:14 AM
Security Audit — agent-trust-hub — brandkit-gen