brand-guidelines-builder
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill utilizes official vendor-provided tools, including the Zapier Model Context Protocol (MCP) server at
https://mcp.zapier.comand the Zapier SDK for workflow management.\n- [SAFE]: Instructions inREADME.md,SKILL.md, andSETUP.mdconsistently mandate human approval for any impactful actions, such as sending messages or updating records, which serves as a critical safety barrier.\n- [SAFE]: The setup instructions inSETUP.mdandONBOARDING-PROMPT.mdfollow security best practices by recommending sanitized test runs and starting with read-only tool configurations.\n- [PROMPT_INJECTION]: The skill processes untrusted external data (design briefs and brand guidelines), which presents an attack surface for indirect prompt injection. Evidence Chain: (1) Ingestion points: Design briefs and brand guidelines are read into the agent context as described inSKILL.mdWorkflow Step 1 and defined inSCHEMA-MAP.md; (2) Boundary markers: None explicitly defined in instructions; (3) Capability inventory: Uses Zapier MCP and SDK for reading brand docs and logging feedback; (4) Sanitization: The risk is mitigated by explicit human approval requirements inREADME.mdand recommendations for sanitized test runs inSETUP.md.
Audit Metadata